Port 27374Sub7
Port 27374 is notoriously associated with Sub7, a popular remote administration trojan from the late 1990s and early 2000s. Sub7 enables a malicious actor to gain covert control of infected Windows machines, allowing unauthorized access, data theft, and remote manipulation. Although its prevalence has declined, the port remains a common scan target for cybercriminals attempting to identify backdoored systems..
- transport
- unknown
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 4,711
single transport
payload readable on path
used by convention
caution
rank 948 of 993 · top 95%
Technical Details
what runs on :27374Sub7 (SubSeven) is a remote access trojan (RAT) historically used to exploit vulnerabilities in Windows operating systems. Once a victim mistakenly executes the malware payload, it installs itself stealthily and opens a backdoor listening on port 27374 by default. This allows attackers to bypass firewall protections and establish unauthorized remote sessions.
The Sub7 client program provides an intuitive graphical interface, enabling the attacker to execute a wide variety of malicious actions such as keystroke logging, file transfers, webcam activation, screenshot capture, and registry edits. Its modular architecture and plugin support further expanded its capabilities, making it a versatile but dangerous tool.
Over time, variants of Sub7 introduced evasion techniques including polymorphic code and encryption of traffic, complicating network detection. However, modern antivirus solutions and Windows security enhancements have reduced the effectiveness of classic Sub7 strains, even though port 27374 continues to be probed by attackers looking for old infections.
Security Information
exposure of :27374risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.8 across 216 ports — this one sits 0.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
unknown
every listening transport is another surface to filter at the edge
security overview
Sub7 open on port 27374 means the potential presence of one of the most well-known remote access trojans. Common vulnerabilities include:
- Backdoors installed through social engineering, phishing, or malware bundles
- Weak or absent endpoint protection allowing payload execution
- Unpatched systems susceptible to privilege escalation
Mitigations include:
- Blocking inbound/outbound connections on port 27374 at firewalls
- Using up-to-date anti-malware to detect and remove RAT components
- Training users to avoid suspicious attachments or downloads
- Regular patching of operating systems and applications
- Conducting network scans to identify unauthorized accessible services
- Employing endpoint detection and response (EDR) solutions for ongoing monitoring
Related Ports
the 8 most looked-up other ports in security — 216 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted