TCP 54321
Synopsis
- Back Orifice 2000 (BO2K), a Windows remote administration Trojan, commonly used TCP port 54321 as the default listen/control port for its backdoor server.
- This port is historically associated with hacking/exploitation: attackers deployed BO2K to control compromised hosts, and internet scans for 54321/TCP have been observed looking for such infections.
- No widely adopted legitimate protocols or mainstream software are known to use TCP/54321 by default.
Observed activity
Last 30 days
Detailed chart