Listado de referencia de puertos TCP y UDP asociados históricamente a troyanos y puertas traseras conocidas. Útil como consulta y para saber qué puertos conviene evitar al configurar aplicaciones como eMule.
Muchos troyanos y puertas traseras (backdoors) se comunican con el atacante a través de puertos de red concretos. Conocer qué puertos se han asociado a malware conocido puede ayudar a identificar tráfico sospechoso y, sobre todo, a evitar esos puertos al configurar tus propias aplicaciones.
Un apunte importante antes de la tabla: que uno de estos puertos esté abierto no significa que estés infectado. La mayoría son también puertos de servicios legítimos (el 80 es la web, el 25 el correo, el 139 recursos compartidos de Windows, etc.). La lista indica coincidencias históricas, no una prueba de infección.
Nota sobre la vigencia de esta lista
Se trata de un listado histórico. La gran mayoría de estos troyanos (Back Orifice, NetBus, SubSeven, Deep Throat, Trinoo…) datan de la época de Windows 9x y XP, entre finales de los años 90 y principios de los 2000, y hoy están prácticamente extintos. El malware actual rara vez usa puertos fijos: emplea puertos dinámicos, se camufla en tráfico HTTPS legítimo o utiliza técnicas mucho más sofisticadas.
Por tanto, esta tabla tiene valor como referencia y como curiosidad de seguridad informática clásica, pero no debe usarse como método de detección de amenazas modernas. Para eso, lo adecuado es un buen antivirus/antimalware actualizado y mantener el sistema al día. Aun así, sigue siendo útil para lo más práctico: comprobar que el puerto que vas a asignar a una aplicación no coincide con uno de esta lista.
Tabla de puertos y troyanos asociados
Salvo que se indique UDP, los puertos corresponden al protocolo TCP.
| Puerto | Protocolo | Troyano(s) asociado(s) |
|---|---|---|
| 1 | UDP | Sockets des Troie |
| 2 | TCP | Death |
| 15 | TCP | B2 |
| 20 | TCP | Senna Spy FTP server |
| 21 | TCP | Back Construction, Blade Runner, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, Fore, FreddyK, Invisible FTP, Juggernaut 42, Larva, MotIv FTP, Net Administrator, Ramen, RTB 666, Senna Spy FTP server, The Flu, Traitor 21, WebEx, WinCrash |
| 22 | TCP | Adore sshd, Shaft |
| 23 | TCP | ADM worm, Fire HacKer, My Very Own trojan, RTB 666, Telnet Pro, Tiny Telnet Server – TTS, Truva Atl |
| 25 | TCP | Ajan, Antigen, Barok, BSE, Email Password Sender – EPS, EPS II, Gip, Gris, Happy99, Hpteam mail, Hybris, I love you, Kuang2, Magic Horse, MBT (Mail Bombing Trojan), Moscow Email trojan, Naebi, NewApt worm, ProMail trojan, Shtirlitz, Stealth, Stukach, Tapiras, Terminator, WinPC, WinSpy |
| 30 | TCP | Agent 40421 |
| 31 | TCP | Agent 31, Hackers Paradise, Masters Paradise |
| 39 | TCP | SubSARI |
| 41 | TCP | Deep Throat, Foreplay |
| 44 | TCP | Arctic |
| 48 | TCP | DRAT |
| 50 | TCP | DRAT |
| 53 | TCP | ADM worm, Lion |
| 58 | TCP | DMSetup |
| 59 | TCP | DMSetup |
| 69 | TCP | BackGate |
| 79 | TCP | CDK, Firehotcker |
| 80 | TCP | 711 trojan (Seven Eleven), AckCmd, Back End, Back Orifice 2000 Plug-Ins, Cafeini, CGI Backdoor, Executor, God Message, God Message 4 Creator, Hooker, IISworm, MTX, NCX, Noob, Ramen, Reverse WWW Tunnel Backdoor, RingZero, RTB 666, Seeker, WAN Remote, Web Server CT, WebDownloader |
| 81 | TCP | RemoConChubo |
| 99 | TCP | Hidden Port, Mandragore, NCX |
| 110 | TCP | ProMail trojan |
| 113 | TCP | Invisible Identd Deamon, Kazimas |
| 119 | TCP | Happy99 |
| 121 | TCP | Attack Bot, God Message, JammerKillah |
| 123 | TCP | Net Controller |
| 133 | TCP | Farnaz |
| 137 | TCP | Chode |
| 137 | UDP | Msinit, Qaz |
| 138 | TCP | Chode |
| 139 | TCP | Chode, God Message worm, Msinit, Netlog, Network, Qaz, Sadmind, SMB Relay |
| 142 | TCP | NetTaxi |
| 146 | TCP | Infector |
| 146 | UDP | Infector |
| 166 | TCP | NokNok |
| 170 | TCP | A-trojan |
| 334 | TCP | Backage |
| 411 | TCP | Backage |
| 420 | TCP | Breach, Incognito |
| 421 | TCP | TCP Wrappers trojan |
| 455 | TCP | Fatal Connections |
| 456 | TCP | Hackers Paradise |
| 511 | TCP | T0rn Rootkit |
| 513 | TCP | Grlogin |
| 514 | TCP | RPC Backdoor |
| 515 | TCP | lpdw0rm, Ramen |
| 531 | TCP | Net666, Rasmin |
| 555 | TCP | 711 trojan (Seven Eleven), Ini-Killer, Net Administrator, Phase Zero, Phase-0, Stealth Spy |
| 600 | TCP | Sadmind |
| 605 | TCP | Secret Service |
| 661 | TCP | NokNok |
| 666 | TCP | Attack FTP, Back Construction, BLA trojan, Cain & Abel, lpdw0rm, NokNok, Satans Back Door – SBD, ServU, Shadow Phyre, th3r1pp3rz (= Therippers) |
| 667 | TCP | SniperNet |
| 668 | TCP | th3r1pp3rz (= Therippers) |
| 669 | TCP | DP trojan |
| 692 | TCP | GayOL |
| 777 | TCP | AimSpy, Undetected |
| 808 | TCP | WinHole |
| 911 | TCP | Dark Shadow |
| 999 | TCP | Chat power, Deep Throat, Foreplay, WinSatan |
| 1000 | TCP | Connecter, Der Späher / Der Spaeher, Direct Connection |
| 1001 | TCP | Der Späher / Der Spaeher, Le Guardien, Silencer, Theef, WebEx |
| 1005 | TCP | Theef |
| 1008 | TCP | Lion |
| 1010 | TCP | Doly Trojan |
| 1011 | TCP | Doly Trojan |
| 1012 | TCP | Doly Trojan |
| 1015 | TCP | Doly Trojan |
| 1016 | TCP | Doly Trojan |
| 1020 | TCP | Vampire |
| 1024 | TCP | Jade, Latinus, NetSpy, Remote Administration Tool – RAT [no 2] |
| 1025 | TCP | Fraggle Rock, md5 Backdoor, NetSpy, Remote Storm |
| 1025 | UDP | Remote Storm |
| 1031 | TCP | Xanadu |
| 1035 | TCP | Multidropper |
| 1042 | TCP | BLA trojan |
| 1042 | UDP | BLA trojan |
| 1045 | TCP | Rasmin |
| 1049 | TCP | /sbin/initd |
| 1050 | TCP | MiniCommand |
| 1053 | TCP | The Thief |
| 1054 | TCP | AckCmd |
| 1080 | TCP | SubSeven 2.2, WinHole |
| 1081 | TCP | WinHole |
| 1082 | TCP | WinHole |
| 1083 | TCP | WinHole |
| 1090 | TCP | Xtreme |
| 1095 | TCP | Remote Administration Tool – RAT |
| 1097 | TCP | Remote Administration Tool – RAT |
| 1098 | TCP | Remote Administration Tool – RAT |
| 1099 | TCP | Blood Fest Evolution, Remote Administration Tool – RAT |
| 1104 | UDP | RexxRave |
| 1150 | TCP | Orion |
| 1151 | TCP | Orion |
| 1170 | TCP | Psyber Stream Server – PSS, Streaming Audio Server, Voice |
| 1174 | TCP | DaCryptic |
| 1180 | TCP | Unin68 |
| 1200 | UDP | NoBackO |
| 1201 | UDP | NoBackO |
| 1207 | TCP | SoftWAR |
| 1208 | TCP | Infector |
| 1212 | TCP | Kaos |
| 1234 | TCP | SubSeven Java client, Ultors Trojan |
| 1243 | TCP | BackDoor-G, SubSeven, SubSeven Apocalypse, Tiles |
| 1245 | TCP | VooDoo Doll |
| 1255 | TCP | Scarab |
| 1256 | TCP | Project nEXT, RexxRave |
| 1269 | TCP | Matrix |
| 1272 | TCP | The Matrix |
| 1313 | TCP | NETrojan |
| 1337 | TCP | Shadyshell |
| 1338 | TCP | Millennium Worm |
| 1349 | TCP | Bo dll |
| 1386 | TCP | Dagger |
| 1394 | TCP | GoFriller |
| 1441 | TCP | Remote Storm |
| 1492 | TCP | FTP99CMP |
| 1524 | TCP | Trinoo |
| 1568 | TCP | Remote Hack |
| 1600 | TCP | Direct Connection, Shivka-Burka |
| 1703 | TCP | Exploiter |
| 1777 | TCP | Scarab |
| 1807 | TCP | SpySender |
| 1826 | TCP | Glacier |
| 1966 | TCP | Fake FTP |
| 1967 | TCP | For Your Eyes Only – FYEO, WM FTP Server |
| 1969 | TCP | OpC BO |
| 1981 | TCP | Bowl, Shockrave |
| 1991 | TCP | PitFall |
| 1999 | TCP | Back Door, SubSeven, TransScout |
| 2000 | TCP | Der Späher / Der Spaeher, Insane Network, Last 2000, Remote Explorer 2000, Senna Spy Trojan Generator |
| 2001 | TCP | Der Späher / Der Spaeher, Trojan Cow |
| 2023 | TCP | Ripper Pro |
| 2080 | TCP | WinHole |
| 2115 | TCP | Bugs |
| 2130 | UDP | Mini Backlash |
| 2140 | TCP | The Invasor |
| 2140 | UDP | Deep Throat, Foreplay |
| 2155 | TCP | Illusion Mailer |
| 2255 | TCP | Nirvana |
| 2283 | TCP | Hvl RAT |
| 2300 | TCP | Xplorer |
| 2311 | TCP | Studio 54 |
| 2330 | TCP | IRC Contact |
| 2331 | TCP | IRC Contact |
| 2332 | TCP | IRC Contact |
| 2333 | TCP | IRC Contact |
| 2334 | TCP | IRC Contact |
| 2335 | TCP | IRC Contact |
| 2336 | TCP | IRC Contact |
| 2337 | TCP | IRC Contact |
| 2338 | TCP | IRC Contact |
| 2339 | TCP | IRC Contact, Voice Spy |
| 2339 | UDP | Voice Spy |
| 2345 | TCP | Doly Trojan |
| 2400 | TCP | Portal of Doom |
| 2555 | TCP | Lion, T0rn Rootkit |
| 2565 | TCP | Striker trojan |
| 2583 | TCP | WinCrash |
| 2589 | TCP | Dagger |
| 2600 | TCP | Digital RootBeer |
| 2702 | TCP | Black Diver |
| 2716 | TCP | The Prayer |
| 2773 | TCP | SubSeven, SubSeven 2.1 Gold |
| 2774 | TCP | SubSeven, SubSeven 2.1 Gold |
| 2801 | TCP | Phineas Phucker |
| 2929 | TCP | Konik |
| 2989 | UDP | Remote Administration Tool – RAT |
| 3000 | TCP | InetSpy, Remote Shut |
| 3024 | TCP | WinCrash |
| 3031 | TCP | Microspy |
| 3128 | TCP | Reverse WWW Tunnel Backdoor, RingZero |
| 3129 | TCP | Masters Paradise |
| 3131 | TCP | SubSARI |
| 3150 | TCP | The Invasor |
| 3150 | UDP | Deep Throat, Foreplay, Mini Backlash |
| 3456 | TCP | Terror trojan |
| 3459 | TCP | Eclipse 2000, Sanctuary |
| 3700 | TCP | Portal of Doom |
| 3777 | TCP | PsychWard |
| 3791 | TCP | Total Solar Eclypse |
| 3801 | TCP | Total Solar Eclypse |
| 4000 | TCP | Connect-Back Backdoor, SkyDance |
| 4092 | TCP | WinCrash |
| 4201 | TCP | War trojan |
| 4242 | TCP | Virtual Hacking Machine – VHM |
| 4321 | TCP | BoBo |
| 4444 | TCP | CrackDown, Prosiak, Swift Remote |
| 4488 | TCP | Event Horizon |
| 4523 | TCP | Celine |
| 4545 | TCP | Internal Revise |
| 4567 | TCP | File Nail |
| 4590 | TCP | ICQ Trojan |
| 4653 | TCP | Cero |
| 4666 | TCP | Mneah |
| 4950 | TCP | ICQ Trogen (Lm) |
| 5000 | TCP | Back Door Setup, BioNet Lite, Blazer5, Bubbel, ICKiller, Ra1d, Sockets des Troie |
| 5001 | TCP | Back Door Setup, Sockets des Troie |
| 5002 | TCP | cd00r, Linux Rootkit IV (4), Shaft |
| 5005 | TCP | Aladino |
| 5010 | TCP | Solo |
| 5011 | TCP | One of the Last Trojans – OOTLT, One of the Last Trojans – OOTLT, modified |
| 5025 | TCP | WM Remote KeyLogger |
| 5031 | TCP | Net Metropolitan |
| 5032 | TCP | Net Metropolitan |
| 5321 | TCP | Firehotcker |
| 5333 | TCP | Backage, NetDemon |
| 5343 | TCP | WC Remote Administration Tool – wCrat |
| 5400 | TCP | Back Construction, Blade Runner |
| 5401 | TCP | Back Construction, Blade Runner, Mneah |
| 5402 | TCP | Back Construction, Blade Runner, Mneah |
| 5512 | TCP | Illusion Mailer |
| 5534 | TCP | The Flu |
| 5550 | TCP | Xtcp |
| 5555 | TCP | ServeMe |
| 5556 | TCP | BO Facil |
| 5557 | TCP | BO Facil |
| 5569 | TCP | Robo-Hack |
| 5637 | TCP | PC Crasher |
| 5638 | TCP | PC Crasher |
| 5742 | TCP | WinCrash |
| 5760 | TCP | Portmap Remote Root Linux Exploit |
| 5802 | TCP | Y3K RAT |
| 5873 | TCP | SubSeven 2.2 |
| 5880 | TCP | Y3K RAT |
| 5882 | TCP | Y3K RAT |
| 5882 | UDP | Y3K RAT |
| 5888 | TCP | Y3K RAT |
| 5888 | UDP | Y3K RAT |
| 5889 | TCP | Y3K RAT |
| 6000 | TCP | The Thing |
| 6006 | TCP | Bad Blood |
| 6272 | TCP | Secret Service |
| 6400 | TCP | The Thing |
| 6661 | TCP | TEMan, Weia-Meia |
| 6666 | TCP | Dark Connection Inside, NetBus worm |
| 6667 | TCP | Dark FTP, EGO, Maniac rootkit, Moses, ScheduleAgent, SubSeven, Subseven 2.1.4 DefCon 8, The Thing (modified), Trinity, WinSatan |
| 6669 | TCP | Host Control, Vampire |
| 6670 | TCP | BackWeb Server, Deep Throat, Foreplay, WinNuke eXtreame |
| 6711 | TCP | BackDoor-G, SubSARI, SubSeven, VP Killer |
| 6712 | TCP | Funny trojan, SubSeven |
| 6713 | TCP | SubSeven |
| 6723 | TCP | Mstream |
| 6767 | TCP | UandMe |
| 6771 | TCP | Deep Throat, Foreplay |
| 6776 | TCP | 2000 Cracks, BackDoor-G, SubSeven, VP Killer |
| 6838 | UDP | Mstream |
| 6883 | TCP | Delta Source DarkStar (??) |
| 6912 | TCP | Shit Heep |
| 6939 | TCP | Indoctrination |
| 6969 | TCP | 2000 Cracks, Danton, GateCrasher, IRC 3, Net Controller, Priority |
| 6970 | TCP | GateCrasher |
| 7000 | TCP | Exploit Translation Server, Kazimas, Remote Grab, SubSeven, SubSeven 2.1 Gold |
| 7001 | TCP | Freak88, Freak2k, NetSnooper Gold |
| 7158 | TCP | Lohoboyshik |
| 7215 | TCP | SubSeven, SubSeven 2.1 Gold |
| 7300 | TCP | NetMonitor |
| 7301 | TCP | NetMonitor |
| 7306 | TCP | NetMonitor |
| 7307 | TCP | NetMonitor, Remote Process Monitor |
| 7308 | TCP | NetMonitor, X Spy |
| 7424 | TCP | Host Control |
| 7424 | UDP | Host Control |
| 7597 | TCP | Qaz |
| 7626 | TCP | Binghe, Glacier, Hyne |
| 7718 | TCP | Glacier |
| 7777 | TCP | God Message, The Thing (modified), Tini |
| 7789 | TCP | Back Door Setup, ICKiller, Mozilla |
| 7826 | TCP | Oblivion |
| 7891 | TCP | The ReVeNgEr |
| 7983 | TCP | Mstream |
| 8080 | TCP | Brown Orifice, Generic backdoor, RemoConChubo, Reverse WWW Tunnel Backdoor, RingZero |
| 8685 | TCP | Unin68 |
| 8787 | TCP | Back Orifice 2000 |
| 8812 | TCP | FraggleRock Lite |
| 8988 | TCP | BacHack |
| 8989 | TCP | Rcon, Recon, Xcon |
| 9000 | TCP | Netministrator |
| 9325 | UDP | Mstream |
| 9400 | TCP | InCommand |
| 9870 | TCP | Remote Computer Control Center |
| 9872 | TCP | Portal of Doom |
| 9873 | TCP | Portal of Doom |
| 9874 | TCP | Portal of Doom |
| 9875 | TCP | Portal of Doom |
| 9876 | TCP | Cyber Attacker, Rux |
| 9878 | TCP | TransScout |
| 9989 | TCP | Ini-Killer |
| 9999 | TCP | The Prayer |
| 10000 | TCP | OpwinTRojan |
| 10005 | TCP | OpwinTRojan |
| 10008 | TCP | Cheese worm, Lion |
| 10067 | UDP | Portal of Doom |
| 10085 | TCP | Syphillis |
| 10086 | TCP | Syphillis |
| 10100 | TCP | Control Total, GiFt trojan |
| 10101 | TCP | BrainSpy, Silencer |
| 10167 | UDP | Portal of Doom |
| 10520 | TCP | Acid Shivers |
| 10528 | TCP | Host Control |
| 10607 | TCP | Coma |
| 10666 | UDP | Ambush |
| 11000 | TCP | Senna Spy Trojan Generator |
| 11050 | TCP | Host Control |
| 11051 | TCP | Host Control |
| 11223 | TCP | Progenic trojan, Secret Agent |
| 11831 | TCP | Latinus |
| 12076 | TCP | Gjamer |
| 12223 | TCP | Hack´99 KeyLogger |
| 12310 | TCP | PreCursor |
| 12345 | TCP | Adore sshd, Ashley, cron / crontab, Fat Bitch trojan, GabanBus, icmp_client.c, icmp_pipe.c, Mypic, NetBus, NetBus Toy, NetBus worm, Pie Bill Gates, ValvNet, Whack Job, X-bill |
| 12346 | TCP | Fat Bitch trojan, GabanBus, NetBus, X-bill |
| 12348 | TCP | BioNet |
| 12349 | TCP | BioNet, Webhead |
| 12361 | TCP | Whack-a-mole |
| 12362 | TCP | Whack-a-mole |
| 12363 | TCP | Whack-a-mole |
| 12623 | UDP | DUN Control |
| 12624 | TCP | ButtMan |
| 12631 | TCP | Whack Job |
| 12754 | TCP | Mstream |
| 13000 | TCP | Senna Spy Trojan Generator |
| 13010 | TCP | BitchController, Hacker Brasil – HBR |
| 13013 | TCP | PsychWard |
| 13014 | TCP | PsychWard |
| 13223 | TCP | Hack´99 KeyLogger |
| 13473 | TCP | Chupacabra |
| 14500 | TCP | PC Invader |
| 14501 | TCP | PC Invader |
| 14502 | TCP | PC Invader |
| 14503 | TCP | PC Invader |
| 15000 | TCP | NetDemon |
| 15092 | TCP | Host Control |
| 15104 | TCP | Mstream |
| 15382 | TCP | SubZero |
| 15858 | TCP | CDK |
| 16484 | TCP | Mosucker |
| 16660 | TCP | Stacheldraht |
| 16772 | TCP | ICQ Revenge |
| 16959 | TCP | SubSeven, Subseven 2.1.4 DefCon 8 |
| 16969 | TCP | Priority |
| 17166 | TCP | Mosaic |
| 17300 | TCP | Kuang2 the virus |
| 17449 | TCP | Kid Terror |
| 17499 | TCP | CrazzyNet |
| 17500 | TCP | CrazzyNet |
| 17569 | TCP | Infector |
| 17593 | TCP | AudioDoor |
| 17777 | TCP | Nephron |
| 18667 | TCP | Knark |
| 18753 | UDP | Shaft |
| 19864 | TCP | ICQ Revenge |
| 20000 | TCP | Millenium |
| 20001 | TCP | Insect, Millenium, Millenium (Lm) |
| 20002 | TCP | AcidkoR |
| 20005 | TCP | Mosucker |
| 20023 | TCP | VP Killer |
| 20034 | TCP | NetBus 2.0 Pro, NetBus 2.0 Pro Hidden, NetRex, Whack Job |
| 20203 | TCP | Chupacabra |
| 20331 | TCP | BLA trojan |
| 20432 | TCP | Shaft |
| 20433 | UDP | Shaft |
| 21544 | TCP | GirlFriend, Kid Terror, Matrix |
| 21554 | TCP | Exploiter, FreddyK, Kid Terror, Schwindler, Winsp00fer |
| 21579 | TCP | Breach |
| 21957 | TCP | Latinus |
| 22222 | TCP | Donald Dick, Prosiak, Ruler, RUX The TIc.K |
| 23005 | TCP | NetTrash, Olive, Oxon |
| 23006 | TCP | NetTrash |
| 23023 | TCP | Logged |
| 23032 | TCP | Amanda |
| 23321 | TCP | Konik |
| 23432 | TCP | Asylum |
| 23456 | TCP | Evil FTP, Ugly FTP, Whack Job |
| 23476 | TCP | Donald Dick |
| 23476 | UDP | Donald Dick |
| 23477 | TCP | Donald Dick |
| 23777 | TCP | InetSpy |
| 24000 | TCP | Infector |
| 24289 | TCP | Latinus |
| 25123 | TCP | Goy’Z TroJan |
| 25555 | TCP | FreddyK |
| 25685 | TCP | MoonPie |
| 25686 | TCP | MoonPie |
| 25982 | TCP | MoonPie |
| 26274 | UDP | Delta Source |
| 26681 | TCP | Voice Spy |
| 27160 | TCP | MoonPie |
| 27374 | TCP | Bad Blood, EGO, Fake SubSeven, Lion, Ramen, Seeker, SubSeven, SubSeven 2.1 Gold, Subseven 2.1.4 DefCon 8, SubSeven 2.2, SubSeven Muie, The Saint, Ttfloader, Webhead |
| 27444 | UDP | Trinoo |
| 27573 | TCP | SubSeven |
| 27665 | TCP | Trinoo |
| 28431 | TCP | Hack´a´Tack |
| 28678 | TCP | Exploiter |
| 29104 | TCP | NetTrojan |
| 29292 | TCP | BackGate |
| 29369 | TCP | ovasOn |
| 29559 | TCP | Latinus |
| 29891 | TCP | The Unexplained |
| 30000 | TCP | Infector |
| 30001 | TCP | ErrOr32 |
| 30003 | TCP | Lamers Death |
| 30005 | TCP | Backdoor JZ |
| 30029 | TCP | AOL trojan |
| 30100 | TCP | NetSphere |
| 30101 | TCP | NetSphere |
| 30102 | TCP | NetSphere |
| 30103 | TCP | NetSphere |
| 30103 | UDP | NetSphere |
| 30133 | TCP | NetSphere |
| 30303 | TCP | Sockets des Troie |
| 30700 | TCP | Mantis |
| 30947 | TCP | Intruse |
| 30999 | TCP | Kuang2 |
| 31221 | TCP | Knark |
| 31335 | TCP | Trinoo |
| 31336 | TCP | Bo Whack, Butt Funnel |
| 31337 | TCP | ADM worm, Back Fire, Back Orifice 1.20 patches, Back Orifice (Lm), Back Orifice russian, Baron Night, Beeone, bindshell, BO client, BO Facil, BO spy, BO2, cron / crontab, Freak88, Freak2k, Gummo, icmp_pipe.c, Linux Rootkit IV (4), Sm4ck, Sockdmini |
| 31337 | UDP | Back Orifice, Deep BO |
| 31338 | TCP | Back Orifice, Butt Funnel, NetSpy (DK) |
| 31338 | UDP | Deep BO, NetSpy (DK) |
| 31339 | TCP | NetSpy (DK) |
| 31557 | TCP | Xanadu |
| 31666 | TCP | BOWhack |
| 31745 | TCP | BuschTrommel |
| 31785 | TCP | Hack´a´Tack |
| 31787 | TCP | Hack´a´Tack |
| 31788 | TCP | Hack´a´Tack |
| 31789 | UDP | Hack´a´Tack |
| 31790 | TCP | Hack´a´Tack |
| 31791 | UDP | Hack´a´Tack |
| 31792 | TCP | Hack´a´Tack |
| 32001 | TCP | Donald Dick |
| 32100 | TCP | Peanut Brittle, Project nEXT |
| 32418 | TCP | Acid Battery |
| 32791 | TCP | Acropolis |
| 33270 | TCP | Trinity |
| 33333 | TCP | Blakharaz, Prosiak |
| 33567 | TCP | Lion, T0rn Rootkit |
| 33568 | TCP | Lion, T0rn Rootkit |
| 33577 | TCP | Son of PsychWard |
| 33777 | TCP | Son of PsychWard |
| 33911 | TCP | Spirit 2000, Spirit 2001 |
| 34324 | TCP | Big Gluck, TN |
| 34444 | TCP | Donald Dick |
| 34555 | UDP | Trinoo (for Windows) |
| 35555 | UDP | Trinoo (for Windows) |
| 37237 | TCP | Mantis |
| 37266 | TCP | The Killer Trojan |
| 37651 | TCP | Yet Another Trojan – YAT |
| 38741 | TCP | CyberSpy |
| 39507 | TCP | Busters |
| 40412 | TCP | The Spy |
| 40421 | TCP | Agent 40421, Masters Paradise |
| 40422 | TCP | Masters Paradise |
| 40423 | TCP | Masters Paradise |
| 40425 | TCP | Masters Paradise |
| 40426 | TCP | Masters Paradise |
| 41337 | TCP | Storm |
| 41666 | TCP | Remote Boot Tool – RBT |
| 44444 | TCP | Prosiak |
| 44575 | TCP | Exploiter |
| 44767 | UDP | School Bus |
| 45559 | TCP | Maniac rootkit |
| 45673 | TCP | Acropolis |
| 47017 | TCP | T0rn Rootkit |
| 47262 | UDP | Delta Source |
| 48004 | TCP | Fraggle Rock |
| 48006 | TCP | Fraggle Rock |
| 49000 | TCP | Fraggle Rock |
| 49301 | TCP | OnLine KeyLogger |
| 50000 | TCP | SubSARI |
| 50130 | TCP | Enterprise |
| 50505 | TCP | Sockets des Troie |
| 50766 | TCP | Fore, Schwindler |
| 51966 | TCP | Cafeini |
| 52317 | TCP | Acid Battery 2000 |
| 53001 | TCP | Remote Windows Shutdown – RWS |
| 54283 | TCP | SubSeven, SubSeven 2.1 Gold |
| 54320 | TCP | Back Orifice 2000 |
| 54321 | TCP | Back Orifice 2000, School Bus |
| 55165 | TCP | File Manager trojan, WM Trojan Generator |
| 55166 | TCP | WM Trojan Generator |
| 57341 | TCP | NetRaider |
| 58339 | TCP | Butt Funnel |
| 60000 | TCP | Deep Throat, Foreplay, Sockets des Troie |
| 60001 | TCP | Trinity |
| 60008 | TCP | Lion, T0rn Rootkit |
| 60068 | TCP | Xzip 6000068 |
| 60411 | TCP | Connection |
| 61348 | TCP | Bunker-Hill |
| 61466 | TCP | TeleCommando |
| 61603 | TCP | Bunker-Hill |
| 63485 | TCP | Bunker-Hill |
| 64101 | TCP | Taskman |
| 65000 | TCP | Devil, Sockets des Troie, Stacheldraht |
| 65390 | TCP | Eclypse |
| 65421 | TCP | Jade |
| 65432 | TCP | The Traitor (= th3tr41t0r) |
| 65432 | UDP | The Traitor (= th3tr41t0r) |
| 65530 | TCP | Windows Mite |
| 65534 | TCP | /sbin/initd |
| 65535 | TCP | Adore worm, RC1 trojan, Sins |
¿Sigue siendo útil buscar puertos de troyanos?
No demasiado, al menos como método de detección. Hace veinte años era habitual que un troyano escuchara siempre en un puerto TCP fijo para recibir conexiones remotas, y por eso una lista como esta servía para detectar posibles infecciones. Hoy la situación ha cambiado por completo.
El malware moderno rara vez usa un puerto fijo. En lugar de esperar conexiones entrantes, la mayoría de las amenazas actuales establecen conexiones salientes hacia servidores de comando y control (C2), y lo hacen camuflándose en protocolos estándar y cifrados que se confunden con el tráfico legítimo:
- HTTPS (443) y HTTP (80), para pasar desapercibidos entre el tráfico web normal.
- DNS (53), mediante técnicas de tunneling.
- Puertos aleatorios distintos en cada infección.
- Servicios en la nube legítimos (Discord, Telegram, GitHub, OneDrive, Google Drive…) como canal de comunicación.
Como resultado, el puerto ya no identifica al malware. Hoy resulta mucho más eficaz analizar el comportamiento: conexiones persistentes o repetitivas (beaconing), tráfico cifrado hacia destinos desconocidos, dominios sospechosos, procesos en ejecución inusuales e indicadores de compromiso (IoC). Familias actuales como AsyncRAT, Quasar, Remcos, njRAT o los frameworks de tipo Cobalt Strike operan precisamente así, y no encajarían en una tabla de puertos fijos.
Por eso esta lista conserva sobre todo un valor de referencia histórica y sigue siendo útil para lo más práctico (comprobar que un puerto que vas a asignar a una aplicación no arrastra mala fama), pero no como herramienta de detección de amenazas modernas.
Recuerda que la mejor defensa frente al malware no es vigilar puertos concretos, sino mantener el sistema operativo y las aplicaciones actualizados, usar software de seguridad de confianza y aplicar buenas prácticas de navegación. La seguridad informática es un esfuerzo continuo que requiere mantenerse informado.