Threat Level: green Handler on Duty: Pedro Bueno

SANS ISC Port Details:


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Graph

[show ascii data]
Graph Criteria
  • Start Date:
  • End Date:
  • Port:
  • Left Y Axis:
  • Right Y Axis:

Port Information

Protocol Service Name
tcp dabber [trojan] Dabber Worm backdoor
tcp monkeycom MonkeyCom
udp monkeycom MonkeyCom
[get complete service list]

User Comment

Submitted By Date
Comment
Shahjahan Khan 2012-09-06 01:15:50
TCP Port 9898 is also used by Tripwire Agent that install on servers to communicate Tripwire Enterprise Servers.
2006-12-31 08:10:43
Also used for TOC/TOC2 (The other AIM protocol), so could cause problems for users if blocked outbound.
Joel Esler 2004-05-18 22:17:32
9898 is one of the backdoor ports used in Sasser. Sasser opens an ftp server on port 9898.
Travis Biehn 2004-05-14 18:03:06
Used by the dabber worm as a backdoor.
Harald Weiss 2004-05-14 01:51:59
9898 TCP has been reported as beeing related to a Backdoor of the Dabber Virus : http://www.lurhq.com/dabber.html for more info
Bill McCarty 2004-02-26 19:07:55
On Feb 25, 2004, I logged several probes of tcp/3127 and tcp/9898. Apparently, there's some association between MyDoom, which plays with tcp/3127, and this port.
Add a comment

CVE Links

CVE # Description