248
Summary
- // if you see it open
- No confirmed malware association per AuditMyPC's port list; a separate uncited, templated secondary source (connected.app) claims C2 abuse but offers no evidence and conflicts with the other source — treated as unverified.
- // analyst note
- treat an open 248/tcp as unexplained; verify with a banner grab rather than assuming either the "clean" or "malware" secondary-source claims.
About port 248/tcp.
Port 248/tcp is registered with IANA under the service name bhfhs, with the description field repeating the same string, "bhfhs," and the assignee/contact listed only as [John_Kelly]. The registry supplies no reference (no RFC), no registration date, and no modification date for this row — those fields are genuinely blank in the live IANA CSV rather than omitted by this write-up. The same entry is dual-registered: 248/udp carries an identical service name, description, and assignee, which is IANA's standard pattern for a single submitter reserving both transports at once rather than evidence of two distinct protocols. Because no specification was ever published for bhfhs, there is no first-party description of what the service does, what software implements it, or why it was reserved; it reads as one of the many individually-registered, never-productized IANA entries from the era before the registry tightened its documentation requirements. Scan-frequency data shows the port is almost never observed open on the public internet, and the handful of secondary "port lookup" sites that discuss it disagree with each other on whether it has any malware history — one flags it as clean, another makes an unsupported claim of C2 abuse. Taken together, an analyst encountering 248/tcp open on a host should treat it as unexplained/anomalous rather than a recognized service, and should not assume the un-cited malware claim is accurate without independent confirmation.
- IANA assignment
bhfhs— description "bhfhs"; reference blank; assignee/contact[John_Kelly]; dual-registered 248/tcp + 248/udp with identical row data [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv- Range class
- well-known (0–1023) [Confirmed] — port number falls in the IANA well-known range by definition
- Prevalence
- nmap-services scan-frequency probability ≈0.000013 for tcp, ≈0.000511 for udp — rarely found open in the wild [Likely] — https://github.com/nmap/nmap (nmap-services file)
- Related ports
- 354/tcp (
bh611) shares the identical IANA contact[John_Kelly], suggesting these may be a small batch of individual registrations rather than a widely adopted protocol family — an inference from cross-referencing two obscure registry rows, not an IANA statement [Likely] — https://www.connected.app/ports/354 ; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Primary use
Unknown/undocumented — the registered name has no RFC, spec, or vendor documentation describing an actual protocol
Other/unofficial uses
none identified in current or historical software
Security implications
no confirmed malware association from the more conservative source; a separate, uncited, templated-language source claims port 248 has been abused for C2, but gives no evidence and conflicts with the other source — treated as unverified, not stated as fact [Likely for "no confirmed malware"; Unknown for the C2 claim] — https://www.auditmypc.com/tcp-port-248.asp ; https://www.connected.app/ports/248
Typically seen on
no known legitimate deployment; an open 248/tcp is an anomaly worth investigating rather than an expected service [Likely]
- Analyst note
- treat an open 248/tcp as unexplained; verify with a banner grab rather than assuming either the "clean" or "malware" secondary-source claims.
About port 248/udp.
Port 248/udp is registered with IANA under the service name bhfhs, with the description field also reading "bhfhs" — an unusual case where the registry does not expand or explain the acronym itself. The assignee and contact are both listed as [John_Kelly], and the port is dual-registered: an essentially identical entry exists for 248/tcp, carrying the same service name, description, and contact, with no other fields populated on either row — no registration date, no modification date, and no formal RFC or reference. This blank pattern is typical of IANA's older, informally-assigned port registrations from the early Internet era, where an individual or small organization requested a service name without publishing a companion specification. Independent web research turned up no documentation clarifying what "bhfhs" stands for, and no mainstream application, protocol stack, or vendor product known to use 248/udp in practice today. No CVE, malware family, or notable scanning/exposure report ties specifically to this port; a general-purpose port-lookup aggregator returns only boilerplate "not currently flagged" status rather than incident-specific evidence, and the port does not appear on commonly-cited high-scan-volume lists. Taken together, 248/udp reads as a dormant, low-prevalence legacy IANA assignment with no confirmed real-world deployment, rather than an actively used or security-relevant service today.
- IANA assignment
- service name
bhfhs, description "bhfhs", assignee/contact [John_Kelly] [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 574); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv - Dual registration
- 248/tcp carries an identical service name/description/contact, all other fields also blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 573)
- Registration date / modification date
- blank in the registry (confirmed blank, not researched-and-lost) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- IANA reference / RFC
- blank — no RFC or specification cited in the registry; none invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Range class
- well-known (0–1023) [Confirmed]
Protocol meaning / expansion
IANA does not expand the acronym; one secondary mirror hinted at a possible private/vendor contact email, uncorroborated by IANA itself
Common software / real-world usage
none identified in this research pass
- Security exposure
- no CVE or malware association found; generic "not flagged" boilerplate from a port-lookup aggregator, not incident-specific evidence; port absent from high-scan-volume lists [Likely] — https://www.auditmypc.com/udp-port-248.asp
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| bhfhs | UDP | — | 0.05% |
| bhfhs | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.