Network port detail · UDP/TCP

121

Erpc
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No active malware campaign found. Undated, low-provenance mirrored 'trojan port' lists associate port 121 with legacy Windows backdoors 'Attack Bot,' 'God Message,' and 'JammerKillah' — no primary AV advisory or dated incident report corroborates. Backdoor:Win32/Ciadoor.121 is a malware variant number, not a reference to port 121, and should not be conflated. A listener on 121/tcp is not expected traffic today.
// analyst note
Treat as a dormant/legacy-registered port for a defunct 1980s parallel-computing protocol. Use neutral, dated language; do not assert active exploitation, and do not backfill an IANA Reference/RFC value beyond the blank the live registry shows.
[ 01 ] — Context

About port 121/tcp.

Updated  ·  Confidence: Medium

Port 121/tcp is registered with IANA as erpc, described as "Encore Expedited Remote Pro.Call," assignee and contact Jack O'Neil, with a blank reference field and dual-registered on both TCP and UDP. ERPC descends from a 1980s low-latency remote-procedure-call design: a functional specification (v1.04, J. Taylor, July 1984) attributes the protocol to Hydra Computer Systems, Inc., which was folded into Encore Computer Corporation, and it shipped as part of Encore's parallel-computing platforms such as the Multimax line (first delivered September 1985). The port name traces back to early "Assigned Numbers" editions — RFC 1010 (1987) lists it under the fuller name "ERPC HYDRA Expedited Remote Procedure Call," later shortened to the current wording — but because the live IANA Reference column is blank, no RFC is recorded here. Encore wound down through the late 1990s and the protocol and its hardware are long defunct, so no legitimate modern use of port 121 is known. For an analyst the port is best treated as a dormant legacy registration: a listener on 121/tcp is not expected traffic. Several mirrored, undated "trojan port" reference lists associate port 121 with early-2000s Windows backdoors ("Attack Bot," "God Message," "JammerKillah"), but no primary AV-vendor advisory or dated incident report corroborates them, and the malware family Backdoor:Win32/Ciadoor.121 uses "121" as a variant number, not a port — the two should not be conflated.

IANA assignment
erpc — "Encore Expedited Remote Pro.Call"; reference (blank — no RFC cited in IANA registry); assignee/contact Jack O'Neil; dual-registered 121/tcp + 121/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (cached snapshot, the IANA Service Name and Transport Protocol Port Number Registry lines 311-312) and iana.org live
Range class
well-known (0–1023) [Confirmed]

Primary use

ERPC (Expedited Remote Procedure Call), a low-latency RPC variant from Hydra Computer Systems (functional spec v1.04, J. Taylor, July 1984), later shipped by Encore Computer Corporation on its parallel-computing platforms (e.g., Multimax, first delivered Sept 1985)

[Likely] — https://www.connected.app/ps/ports/121 (single secondary source)

Common software

Unknown / none identified [Unknown]

Security implications

no active malware campaign found for port 121. Undated, low-provenance mirrored "trojan port" lists tie it to legacy Windows backdoors "Attack Bot," "God Message," and "JammerKillah"; no primary AV advisory or dated incident report corroborates these. Backdoor:Win32/Ciadoor.121 is a malware variant number, not a reference to port 121 — do not conflate [Likely / Threat-reported] — https://www.connected.app/ps/ports/121; https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:Win32/Ciadoor.121

Typically seen on

no expected modern host class; a listener on 121/tcp on the open internet is anomalous

Historical reference
RFC 1010 "Assigned Numbers" (1987) lists the port as "ERPC HYDRA Expedited Remote Procedure Call"; the live IANA Reference field is blank, so no RFC is recorded as the IANA reference [Likely] — https://www.connected.app/ps/ports/121; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Current legitimate usage
none known. Encore Computer Corporation effectively ceased to exist by 1999; ERPC and its hardware are discontinued, and no modern software or vendor is known to bind port 121 for a legitimate service [Likely] — https://www.connected.app/ps/ports/121
Analyst note
Treat as a dormant/legacy-registered port for a defunct 1980s parallel-computing protocol. Use neutral, dated language; do not assert active exploitation, and do not backfill an IANA Reference/RFC value beyond the blank the live registry shows.
[ 02 ] — Context

About port 121/udp.

Updated  ·  Confidence: Medium

Port 121/udp is registered with IANA as erpc with the description "Encore Expedited Remote Pro.Call," assignee "Jack O'Neil," and a blank reference field; the same erpc entry is dual-registered on both 121/tcp and 121/udp with identical service name, description, and assignee. ERPC — Expedited Remote Procedure Call — traces to a lightweight, low-latency RPC variant that secondary sources attribute to Hydra Computer Systems, Inc. (functional spec v1.04, J. Taylor, July 1984) for tightly-coupled multiprocessor systems; Hydra was acquired by Encore Computer Corporation, which is why the IANA description reads "Encore Expedited Remote Pro.Call." Encore Computer Corporation effectively ceased operating by around 1999, and no current, actively-maintained software or service was found that legitimately uses port 121/udp — multiple port-reference sources describe it as effectively dead in modern deployments. For an analyst, the practical relevance is almost entirely historical: because no legitimate modern service claims this port, several legacy "trojan port" reference lists — a well-known genre of early-2000s security documentation — associate port 121 with older Windows backdoors, namely "Attack Bot," "God Message" (an ActiveX trojan targeting Windows 95/98/ME/NT/2000), and "JammerKillah." These associations appear consistently across independent legacy port guides, but none of them distinguishes TCP from UDP, none is a primary or authoritative threat-intelligence source (no vendor advisory or CVE), and no current 2020s-era scanning or honeypot telemetry specific to 121/udp was located. Treat a responsive 121/udp as an anomaly worth investigating — a dated, secondary-sourced malware signal or a decoy — rather than a normal service.

IANA assignment
erpc — "Encore Expedited Remote Pro.Call"; reference (blank — no RFC cited in IANA registry); assignee Jack O'Neil; dual-registered 121/tcp + 121/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=3); the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Registration / modification date
Unknown — IANA's service-names registry publishes no per-entry assignment date for this row; not inferred [Unknown] — IANA registry
IANA reference (RFC)
blank — no RFC is listed for this entry [Confirmed] — IANA registry
Related ports
the small/legacy RPC and vendor-service cluster; contrast modern RPC discovery

Primary use

ERPC (Expedited Remote Procedure Call), a low-latency RPC variant traced to a Hydra Computer Systems 1984 functional spec (J. Taylor); Hydra was acquired by Encore Computer Corporation, hence the "Encore" naming

[Likely] — https://www.connected.app/ps/ports/121

Common software today

Unknown / none identified — no actively-maintained service was found using 121/udp; multiple sources describe it as effectively dead

[Likely] — https://www.connected.app/ps/ports/121, https://kb.eventtracker.com/evtpass/evtPages/PortNo_121_erpc_54558.asp

Security implications

legacy "trojan port" lists associate port 121 with older Windows backdoors — "Attack Bot," "God Message" (ActiveX trojan, Win 95/98/ME/NT/2000), "JammerKillah"; corroborated across multiple independent legacy port guides but none is primary threat intel, none distinguishes TCP vs UDP, and no current scanning telemetry was found — dated, secondary-sourced, historical signal [Likely] — https://www.pc-freak.net/exploitworld/info/trojans_info/trojans.html, https://github.com/brandonprry/rising_sun/blob/master/AutoAssess.Data.BusinessObjects/rsc/suspicious_ports

Typically seen on

no legitimate modern host profile identified; a responsive 121/udp is an anomaly / possible decoy or backdoor

Current scanning context (2026)
Unknown — no dated 2024–2026 scan/honeypot data specific to 121/udp was located; none fabricated [Unknown]
Analyst note
An open 121/udp is statistically rare with no known legitimate modern service — treat as a historical/secondary malware signal or a decoy and investigate; legitimate use is unlikely.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
erpc UDP Encore Expedited Remote Pro.Call 0.07%
erpc TCP Encore Expedited Remote Pro.Call 0.00%
IANA name
erpc
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.