Network port detail · UDP/TCP

207

At-7
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Not found in Gary Kessler's Bad Ports list, Trend Micro's Trojan Ports glossary, or mthcht's suspicious-ports list; absence is unconfirmed rather than a verified clean bill. No malware/trojan association identified.
// analyst note
A responsive port 207/tcp is statistically negligible and has no known legitimate deployment — treat any observed traffic as an anomaly or scan artifact worth investigating rather than a recognized service.
[ 01 ] — Context

About port 207.

Updated  ·  Confidence: Medium

Port 207/tcp is registered with IANA under the service name at-7, described simply as "AppleTalk Unused." The registry entry is dual-registered — 207/udp carries the identical service name and description — and every field beyond service name and description (assignee, contact, registration date, modification date, IANA reference) is blank in the canonical registry. This places port 207 inside a contiguous block, roughly 200 through 208, that IANA carved out for AppleTalk-related service names during the era when Apple was registering AppleTalk-over-IP service slots (at-1 through at-8, alongside related at-echo/at-nbp/at-zis entries); 207 itself, however, was never assigned to an active protocol implementation and has remained a placeholder ever since. There is no RFC or other reference document behind it, and no vendor or open-source project is documented as using it. Nmap's nmap-services frequency file — built from real internet-wide scan telemetry — records essentially zero observed exposure: 0.000000 for TCP and 0.001351 for UDP, meaning a host answering on 207/tcp is a scanning artifact or a highly unusual configuration rather than a recognized service. Checks against Gary Kessler's Bad Ports list, Trend Micro's Trojan Ports glossary, and mthcht's suspicious-ports compilation turned up no malware or trojan association, though that absence is not itself a guarantee of safety — it simply means no public list currently flags this port. For an analyst, 207/tcp should be treated as a dead AppleTalk-era reservation: any observed traffic or open listener on it is noteworthy precisely because it defies the port's near-total historical inactivity.

IANA assignment
at-7 — "AppleTalk Unused"; reference (blank — no RFC cited); assignee/contact blank; dual-registered 207/tcp + 207/udp, identical fields [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 500–501); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Range class
well-known (0–1023)
Prevalence
nmap-services open-frequency 207/tcp ≈ 0.000000, 207/udp ≈ 0.001351 (essentially never observed open in internet-wide scans) [Confirmed] — https://svn.nmap.org/nmap/nmap-services
Related ports
The AppleTalk port block 200–208 (at-1 through at-8 and related at-echo/at-nbp/at-zis entries)

Primary use

None active — reserved as part of the AppleTalk port block but never assigned a running protocol ("Unused")

[Confirmed] — IANA registry

Other/unofficial uses

Sits within the AppleTalk-over-IP port series (approx. 200–208, at-1 through at-8) from Apple's IANA registration wave; no independent unofficial use identified

[Likely] — inferred from adjacent registry entries, not independently sourced

Security implications

Not found in Gary Kessler's Bad Ports list, Trend Micro's Trojan Ports glossary, or mthcht's suspicious-ports list — no malware/trojan association identified, but absence from these lists is not a verified clean bill [Unknown] — https://www.garykessler.net/library/bad_ports.html, https://docs.trendmicro.com/all/ent/officescan/v10.5/en-us/osce_10.5_olhcl/osce_topics/what_are_trojan_ports_.htm, https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_ports_list.csv

Typically seen on

No hosts or software documented as running this service; essentially never observed open

[Likely] — nmap-services frequency data
Analyst note
A responsive port 207/tcp is statistically negligible and has no known legitimate deployment — treat any observed traffic as an anomaly or scan artifact worth investigating rather than a recognized service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
at-7 UDP AppleTalk Unused 0.14%
at-7 TCP AppleTalk Unused 0.00%
IANA name
at-7
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.