Hey y'all
I got a sub/seven trojan alert on my firewall, and I port scanned the IP it came from. My portscanner found all kinds of open ports. This is interesting (at least to me). Port 1960 was open. My port scanner had this message reference port 1960:

port 1960 connected.time/date: 00:59:59 March 3, 2002, Sunday version: DEFCON8 2:1

I put DEFCON8 in my search engine and it seems it's some kind of sub-seven trojan version. Is that right? Does this mean the 'puter that attacked me is running this trojan on port 1960? And does that mean it's probably a "zombie" some cracker is using to run attacks through? Let me know what you think.