198
Summary
- // if you see it open
- No documented malware family or scanning campaign tied specifically to this port. A low-authority site (auditmypc.com) carries generic templated 'no known virus/trojan' disclaimer language, not treated as a verified finding.
- // analyst note
- dls-mon is an obscure, apparently-dormant legacy registration with no confirmed modern usage; an open port 198 is statistically unusual and merits investigation rather than being assumed benign.
About port 198/tcp.
Port 198/tcp is registered with IANA as dls-mon, described as "Directory Location Service Monitor," with assignee Scott Bellew and a blank reference field; the registration is dual-listed on both TCP and UDP (198/udp carries the identical name, description, and assignee). No RFC or other IETF specification document is attached to this entry in the registry, and no reference number is listed — that blank is left blank here rather than invented. The name and its numeric proximity to port 197/tcp+udp (dls, "Directory Location Service") strongly suggest dls-mon was intended as a monitoring or status-check companion channel for that service, though no protocol document or independent source confirms the exact relationship, so this pairing is treated as a likely inference rather than a confirmed fact. No mainstream server or client software, open-source or commercial, is documented as implementing dls-mon today, and it does not appear as an active service in common service-fingerprint databases such as nmap-services beyond the bare name inherited from the IANA list. No credible, named malware family or documented internet-wide scanning campaign is tied specifically to this port; a low-authority consumer site (auditmypc.com) carries generic templated "no known virus/trojan" boilerplate that is repeated across many of that site's port pages and is not treated as a verified security finding. Given its obscurity and the total absence of documented real-world deployment, port 198/tcp should be treated by an analyst as an essentially unused legacy registration — a responsive listener on this port is unusual and worth investigating as an anomaly rather than assumed to be the registered service.
- IANA assignment
dls-mon— "Directory Location Service Monitor"; reference (blank — no RFC cited in IANA registry); assignee Scott Bellew; dual-registered 198/tcp + 198/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- no authoritative open-frequency figure located for this port; assessed as extremely rare/essentially unused given the absence of any documented real-world deployment [Unknown]
- Related ports
- 197/tcp + 197/udp (
dls, Directory Location Service — the likely paired registration)
Primary use
legacy IANA registration with no attached RFC; name and numeric adjacency to port 197 (dls, Directory Location Service) suggest it was meant as a monitoring/status companion channel for that service, but no protocol document confirms this
Other/unofficial uses
none identified; no modern software or protocol implementation documented [Unknown]
Security implications
no documented malware family or scanning campaign tied to this port specifically; a low-authority site (auditmypc.com) carries generic templated "no known virus/trojan" disclaimer language not treated as a verified finding
Typically seen on
not documented as deployed on any current OS or software package; a responsive instance would be an anomaly [Unknown]
- Analyst note
- dls-mon is an obscure, apparently-dormant legacy registration with no confirmed modern usage; an open port 198 is statistically unusual and merits investigation rather than being assumed benign.
About port 198/udp.
Port 198/udp is registered with IANA as dls-mon, "Directory Location Service Monitor," under assignee and contact Scott Bellew, with no registration date, modification date, or RFC/reference recorded in the registry — an artifact of IANA's early service-name assignment era rather than a gap in our data. The registration is dual: 198/tcp carries the identical name, description, and assignee, a pattern common to services registered before transport protocols were tracked separately. The name implies dls-mon was intended as a monitoring or status-check companion to a "Directory Location Service" (DLS) — presumably an early enterprise directory or name-resolution product from the 1990s IANA registration era — but no IETF RFC, vendor manual, or independent technical description of the protocol surfaced during research; the bare registry line (name, one-sentence description, registrant) is the only first-party documentation available. Third-party port-lookup mirrors (t1shopper, adminsub.net, auditmypc) simply republish the same IANA text without adding software attribution, so "common software" for this port should be treated as unknown rather than asserting a specific product. No CVEs, malware-family associations, or notable internet-scanning campaigns reference port 198 in current security literature, and its footprint in available scan data is slight — the nmap-services dataset records an observed open-frequency of ≈ 0.001252 for 198/udp (roughly 1 in 1,000 sampled hosts) against 0 for 198/tcp, consistent with a legacy, rarely-if-ever-implemented registration answering the occasional scan. For an analyst, a host responding on 198/udp is unusual enough to warrant investigation as a fingerprint or anomaly rather than routine traffic, though absent further evidence this remains a low-visibility, low-confidence corner of the port space.
- IANA assignment
dls-mon— "Directory Location Service Monitor"; reference (blank — no RFC cited in IANA registry); assignee/contact [Scott_Bellew]; dual-registered 198/tcp + 198/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (matching 198/tcp at line 482); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services observed open-frequency 198/udp ≈ 0.001252 — very low (roughly 1 in 1,000 sampled hosts), 298th of 5,615 UDP entries; the TCP sibling 198/tcp records 0. The figure measures how often the port answers a scan, not dls-mon use — no source identifies what is listening[Likely] — nmap-services dataset
- Related ports
- 198/tcp (identical dual registration, same assignee/contact, same blank date/reference fields) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
presumed monitoring/status companion to an unspecified "Directory Location Service" product
Other/unofficial uses
none documented
Security implications
no CVEs, malware associations, or notable scanning campaigns documented for port 198 as of 2026-07-11; absence of evidence, not a confirmed zero-risk finding [Unknown]
Typically seen on
unknown — no current or historical client/server software confirmed [Unknown]
- Analyst note
- A responsive port 198/udp is a legacy, low-footprint registration with no known modern usage; treat an unexpected open instance as an anomaly worth investigating rather than routine traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dls-mon | UDP | Directory Location Service Monitor | 0.13% |
| dls-mon | TCP | Directory Location Service Monitor | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.