Event ID - 6667

Port No6667
Service NameDark FTP
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows 95, 98 and NT, together with an IRC program and any FTP software. ˆ Source code is available.
Reference LinkDark FTP Trojan
AttackIt autoloads the Registry:
HLM\Software\Microsoft\Windows\CurrentVersion\Run\ HLM\Software\DataLogic\ActiveSubControl\

It does the following :
1.FTP server
2. IRC trojan
Kills the firewall atGuard. The hacker is able to restart or shut the server down through IRC.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.