Legacy Symantec AntiVirus management agent — the port the "Big Yellow" worm hunted.
2967 is registered as ssc-agent and is the port Symantec AntiVirus Corporate Edition and Symantec Client Security used for management communication with rtvscan.exe, the real-time scanner service. In 2006 the Sagevo ("Big Yellow") worm scanned the internet for 2967 and installed a bot on unpatched clients by exploiting CVE-2006-2630, a stack-based buffer overflow in Symantec AntiVirus 10.1 and Client Security 3.1; Metasploit's module for it targets exactly this port. Scanning noise on 2967 has never fully died down, and it remains one of the more commonly probed non-obvious ports.
Do not expose
An endpoint-security management agent running with system privileges, with a wormed remote code execution in its history — internal management network only, on supported software.
$ nc -vz -w 3 TARGET 2967Seen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.
Get Beige Box →also available as JSON · Markdown
Corrections or a missing port? Reply @rimrocksystems.