Network port detail · UDP/TCP

208

At-8
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No confirmed malware family or documented exploitation tied specifically to port 208/tcp. Port-checker aggregator sites list generic templated 'trojan/virus' disclaimer text reused across all their port pages, not a 208-specific finding, so it is not treated as a substantiated signal. An open/listening 208/tcp is anomalous relative to any known legitimate service and warrants investigation on its own merits.
[ 01 ] — Context

About port 208/tcp.

Updated  ·  Confidence: Medium

Port 208/tcp is registered with IANA under the service name at-8, with the literal description "AppleTalk Unused," assignee and contact both listed as Rob Chandhok, and no RFC or reference document cited. The entry is dual-registered: 208/udp carries an identical service name, description, and assignee, and both rows leave the Registration Date, Modification Date, Reference, and Service Code columns blank in the IANA CSV — those blanks are reported here as-is rather than inferred or backfilled with a plausible-looking date or RFC. The at-8 name sits in a small cluster of AppleTalk-prefixed reservations IANA made in its early port-registry era (names such as at-rtmp, at-nbp, at-echo, and at-zis occupy nearby port numbers), and the description "Unused" is IANA's own characterization — the number was set aside for a possible AppleTalk sub-protocol slot that was never actually specified or bound to a running service. Consistent with that, no mainstream operating system, daemon, or well-known server product documents listening on TCP port 208; Wikipedia's List of TCP and UDP port numbers, which is fairly exhaustive for the well-known range, has no entry for 208 at all, jumping from 201 to 209. Generic port-checker aggregator sites list the port but their malware-association language is templated boilerplate repeated across all of their port pages, not a finding specific to 208, so it is not treated as a substantiated security signal. No dated exposure/scan-prevalence statistic (e.g., Shodan/Censys-style counts) could be found or verified in this pass, so that field is left Unknown rather than estimated. Net effect for an analyst: a responsive 208/tcp is not tied to any known legitimate service or documented malware family, so it should be treated as anomalous and investigated on its own merits rather than pattern-matched to a known signature.

IANA assignment
at-8 — "AppleTalk Unused"; assignee/contact Rob Chandhok; reference field blank (no RFC cited); dual-registered 208/tcp + 208/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-503; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5
Registration/Modification dates
blank in the IANA source; left blank, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed] — port number itself
Prevalence/exposure
Unknown — no dated scan-prevalence (Shodan/Censys-style) source found or verified [Unknown]
Related ports
nearby early AppleTalk-placeholder reservations (at-rtmp, at-nbp, at-echo, at-zis) [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5

Primary use

reserved as part of an early-registry cluster of AppleTalk placeholder names (at-rtmp, at-nbp, at-echo, at-zis, at-8) but never bound to an active AppleTalk sub-protocol; IANA's own description is "Unused" [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5; https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

Common software

none identified; Wikipedia's List of TCP and UDP port numbers has no entry for 208 (table jumps 201→209)

[Likely] — https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

Security implications

no confirmed malware family or documented exploitation tied specifically to 208/tcp; generic port-checker aggregator "trojan/virus" language is templated disclaimer text reused across all their port pages, not a 208-specific finding, so it is not cited as a real security signal

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5

Typically seen on

no known legitimate deployment; an open 208/tcp is anomalous and worth investigating rather than pattern-matched to a known service [Likely]

[ 02 ] — Context

About port 208/udp.

Updated  ·  Confidence: Medium

Port 208/udp is registered with IANA under the service name at-8, with the literal description "AppleTalk Unused," assignee and contact both listed as Rob Chandhok, and no RFC or reference document cited. The row is dual-registered: 208/tcp carries an identical service name, description, and assignee, and both rows leave the Registration Date, Modification Date, Reference, and Service Code columns blank in the IANA CSV — those blanks are reported here as-is rather than inferred or backfilled with a plausible-looking date or RFC. The wider AppleTalk-prefixed cluster of low port numbers (at-rtmp on 201, at-nbp, at-echo, at-zis, and others in the 200s) traces back to an April 1988 NIC assignment of a UDP port range for AppleTalk's DDP well-known sockets, per Cisco's IOS AppleTalk documentation; that source names at-nbp, at-rtmp, at-echo, and at-zis explicitly but does not name at-8 among the original 1988 batch, so 208/udp is treated here as part of the same broader AppleTalk numbering cluster rather than confirmed as one of the four ports assigned that specific month — a distinction worth preserving rather than smoothing over. Consistent with IANA's own "Unused" description, no mainstream operating system, daemon, or well-known server product documents listening on UDP port 208, and Wikipedia's List of TCP and UDP port numbers has no entry for 208 at all (its table jumps from 201 to 209). Generic port-checker aggregator sites (e.g., auditmypc.com) list UDP 208 with a "flagged as a virus/Trojan" warning, but this language is templated boilerplate applied uniformly across their port-database pages regardless of the specific port, not a finding specific to 208, so it is not treated as a substantiated security signal. The nmap-services dataset records an observed open-frequency of roughly 0.000511 for 208/udp and 0.000000 for 208/tcp, very low in absolute terms; beyond that figure no dated Shodan/Censys-style exposure count could be found or verified, and none is estimated here. As a connectionless UDP service with no bound listener, an unsolicited probe to 208/udp typically draws no response at all (unlike TCP's RST-on-closed-port behavior), so internet-wide UDP scanners generally have little basis to report it as "open," and a response would be unusual enough to warrant investigation on its own merits rather than pattern-matching to a known service or malware family.

IANA assignment
at-8 — "AppleTalk Unused"; assignee/contact Rob Chandhok; reference field blank (no RFC cited); dual-registered 208/tcp + 208/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5
Registration/Modification dates
blank in the IANA source; left blank, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed] — port number itself
Prevalence/exposure
nmap-services observed open-frequency 208/udp ≈ 0.000511 (very low — roughly 5 in 10,000 scanned hosts in the nmap-services sample) [Confirmed] — nmap-services dataset; the dual-registered 208/tcp row records 0.000000 in the same dataset [Confirmed] — nmap-services dataset. Beyond that figure, no dated Shodan/Censys-style exposure count was found or verified [Unknown]; as an unbound UDP port, closed-port probes typically draw no response, further suppressing scanner visibility [Likely]
Related ports
208/tcp (dual-registered, identical fields); nearby AppleTalk-placeholder reservations (at-rtmp/201, at-nbp, at-echo, at-zis) [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5

Primary use

reserved as part of the broader AppleTalk-prefixed placeholder cluster in the low 200s but never bound to an active AppleTalk sub-protocol; IANA's own description is "Unused"

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5

Common software

none identified; Wikipedia's List of TCP and UDP port numbers has no entry for 208 (table jumps 201→209)

[Likely] — https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

Security implications

no confirmed malware family or documented exploitation tied specifically to 208/udp; auditmypc.com and similar aggregator sites show a generic "flagged as virus" warning that is templated disclaimer text reused across their port pages, not a 208-specific finding, so it is not cited as a real security signal

[Likely] — https://www.auditmypc.com/udp-port-208.asp

Typically seen on

no known legitimate deployment; a responsive 208/udp is anomalous and worth investigating rather than pattern-matched to a known service, especially since UDP's connectionless design makes an actual response less likely than on TCP [Likely]

Historical context
the AppleTalk 200-range UDP ports trace to an April 1988 NIC assignment for DDP well-known sockets, naming at-nbp, at-rtmp, at-echo, and at-zis explicitly; at-8/208 is not named in that specific passage, so its inclusion in the original 1988 batch (vs. a later addition to the same numbering cluster) is Unknown [Confirmed re: the 1988 assignment itself; Unknown re: whether 208 was part of it] — https://docstore.mik.ua/univercd/cc/td/doc/product/software/ssr83/rpc_r/48379.htm
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
at-8 UDP AppleTalk Unused 0.05%
at-8 TCP AppleTalk Unused 0.00%
IANA name
at-8
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.