TCP Port 7000 – afs3-fileserver
About TCP Port 7000
The Internet Assigned Numbers Authority (IANA) registers port 7000 for afs3-fileserver. The IANA description reads: ‘file server itself’. This port is referenced in 2049 IDS rules and exhibits moderate malware activity in monitored traffic.
IDS Rule References
2049 IDS / security rules reference TCP port 7000. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 6): trojan-activity (729), web-application-activity (476), web-application-attack (344), attempted-recon (270), misc-activity (76), attempted-user (59).
Sample rule descriptions for TCP port 7000:
- SERVER-OTHER CHAT IRC topic overflow
- SERVER-WEBAPP PCCS mysql database admin tool access
- POLICY-SOCIAL IRC nick change
- SERVER-WEBAPP HyperSeek hsx.cgi directory traversal attempt
- SERVER-WEBAPP SWSoft ASPSeek Overflow attempt
Malware Activity
A meaningful share of monitored traffic on this port involves malware indicators.
683 of 2049 IDS rules for TCP port 7000 involve malware activity.
Families observed (top 8): Bancos (20), Fareit (15), Zeus (15), DesertFalcon (11), Symmi (11), Zebrocy (11), Chopper (10), Locky (9), and 262 more families.
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
