133
Summary
- // if you see it open
- No CVE, vendor advisory, or named threat-intelligence source ties a malware family to TCP port 133; no malware association is confirmed.
- // analyst note
- treat an open 133/tcp as an uncommon/legacy port worth generic investigation; no confirmed malware association exists for this port.
About port 133/tcp.
Port 133/tcp is registered with IANA as statsrv with the description "Statistics Service," assignee and contact listed as Dave Mills, and a blank reference field; the identical service name, description, assignee, and contact are also registered on 133/udp, with both rows leaving Registration Date, Modification Date, and Reference blank in the registry. Dave Mills is a well-known early figure in Internet protocol history (notably the designer of NTP and the Fuzzball router/host software used on the early ARPANET/NSFNET), which situates statsrv among a cluster of early well-known-ports entries assigned to individual protocol authors rather than to an organization or company, typical of the pre-1992 era of the ports registry. No RFC or other IANA reference document is cited for this entry, and no widely documented, still-maintained client/server protocol specification for statsrv was found — it does not correspond to a well-known modern service or common daemon in current use. No malware or trojan association is confirmed for TCP port 133: no CVE, vendor advisory, or named threat-intelligence source ties a malware family to this port. For an analyst, port 133 today is best treated as a legacy/reserved IANA entry with no confirmed active mainstream use; an unexpected open 133/tcp warrants the same generic scrutiny given to any rarely-seen open port rather than being read as an indicator of malware.
- IANA assignment
statsrv— "Statistics Service"; reference blank (no RFC cited); assignee/contact Dave Mills; dual-registered 133/tcp + 133/udp with identical fields [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 343–344); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml- Range class
- well-known (0–1023)
- Registration/modification dates
- Unknown — blank in the IANA registry for both tcp and udp rows; no date fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Related ports
- other early Dave-Mills-era / legacy well-known-port assignments in the same registry range
Primary use
legacy/historical Internet service name from the early well-known-ports era; no actively maintained protocol specification or common modern implementation identified [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml; http://www.t1shopper.com/tools/port-number/133/
Common software
none identified in current mainstream use; aggregator sites echo the IANA label without naming an implementing daemon
Security implications
no confirmed malware association — no CVE, vendor advisory, or named threat-intelligence source ties a malware family to TCP 133
Typically seen on
rarely observed in the wild; no confirmed modern host role
- Analyst note
- treat an open 133/tcp as an uncommon/legacy port worth generic investigation; no confirmed malware association exists for this port.
About port 133/udp.
Port 133/udp is registered with IANA as statsrv, described as "Statistics Service," with assignee and contact listed as Dave_Mills_2; the Reference field in the current registry snapshot is blank, and 133/tcp carries the identical dual registration (same name, description, and assignee). Independent of that blank Reference field, the underlying protocol has a clear origin: RFC 996, "Statistics Server," published by J. Reynolds in February 1987, defines a simple client/server exchange over both 133/tcp and 133/udp for casual host or gateway monitoring, with Dave Mills (then at the University of Delaware) named as the contact. The design is intentionally lightweight — a client sends ASCII commands and receives ASCII responses reporting basic host statistics — and the RFC is explicit that it was never meant to be a fully standardized, machine-parseable monitoring protocol; it reads more like an ad hoc debugging aid from the same mid-1980s research context that also produced Mills's early NTP work. There is no evidence the service saw meaningful production deployment: no current software, daemon, or client implementing statsrv turns up in general searches, and the port does not appear on common scanned-port or exploited-port lists, nor in vendor security advisories. Generic port-lookup reference sites simply restate the IANA name and description without adding operational or security detail. For an analyst, 133/udp should be treated as a legacy, effectively unused IANA assignment: a responsive host on this port would be unusual and worth noting as an anomaly rather than assumed to be a live statsrv implementation, since no contemporary use case or exploitation history is documented.
- IANA assignment
statsrv— "Statistics Service"; assignee/contact Dave_Mills_2; Reference field blank in registry; dual-registered 133/tcp + 133/udp with identical name/description/assignee [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 344 (udp), line 343 (tcp); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023) [Confirmed]
- IANA Reference column
- blank in the live registry entry — not backfilled with RFC 996 since IANA itself does not cite a reference there; left blank per house no-fabrication rule [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 344
- Registration/modification dates
- Unknown — blank in the registry, not recorded [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 344
- Related ports
- 133/tcp (identical dual registration); other legacy Dave Mills-era small services
Primary use / protocol origin
RFC 996 "Statistics Server" (J. Reynolds, February 1987) — ASCII command/response exchange over 133/tcp and 133/udp for casual host/gateway statistics monitoring; explicitly not a full standardized machine-parseable protocol
Common software / modern implementations
Unknown — no current daemon, client, or production software documented as implementing statsrv; appears to be an unused 1980s-era experimental protocol [Unknown]
Typically seen on
essentially nowhere in modern deployments; a responsive host is anomalous
- Security / scanning notability
- Unknown — no port-133-specific findings in scanning writeups, exploit databases, or Shodan-style port lists; generic reference sites (SpeedGuide, T1 Shopper, adminsub.net, EventTracker KB) only restate the IANA name/description [Unknown] — https://www.speedguide.net/port.php?port=133, http://www.t1shopper.com/tools/port-number/133/, https://www.adminsub.net/tcp-udp-port-finder/133, http://kb.eventtracker.com/evtpass/evtPages/PortNo_133_statsrv_9458.asp
- Analyst note
- Treat any response on 133/udp as an anomaly or possible fingerprint/decoy rather than an active statsrv deployment, given the absence of documented modern use.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| statsrv | UDP | Statistics Service | 0.08% |
| statsrv | TCP | Statistics Service | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.