Network port detail · UDP/TCP

248

Bhfhs
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No confirmed malware association per AuditMyPC's port list; a separate uncited, templated secondary source (connected.app) claims C2 abuse but offers no evidence and conflicts with the other source — treated as unverified.
// analyst note
treat an open 248/tcp as unexplained; verify with a banner grab rather than assuming either the "clean" or "malware" secondary-source claims.
[ 01 ] — Context

About port 248/tcp.

Updated  ·  Confidence: Medium

Port 248/tcp is registered with IANA under the service name bhfhs, with the description field repeating the same string, "bhfhs," and the assignee/contact listed only as [John_Kelly]. The registry supplies no reference (no RFC), no registration date, and no modification date for this row — those fields are genuinely blank in the live IANA CSV rather than omitted by this write-up. The same entry is dual-registered: 248/udp carries an identical service name, description, and assignee, which is IANA's standard pattern for a single submitter reserving both transports at once rather than evidence of two distinct protocols. Because no specification was ever published for bhfhs, there is no first-party description of what the service does, what software implements it, or why it was reserved; it reads as one of the many individually-registered, never-productized IANA entries from the era before the registry tightened its documentation requirements. Scan-frequency data shows the port is almost never observed open on the public internet, and the handful of secondary "port lookup" sites that discuss it disagree with each other on whether it has any malware history — one flags it as clean, another makes an unsupported claim of C2 abuse. Taken together, an analyst encountering 248/tcp open on a host should treat it as unexplained/anomalous rather than a recognized service, and should not assume the un-cited malware claim is accurate without independent confirmation.

IANA assignment
bhfhs — description "bhfhs"; reference blank; assignee/contact [John_Kelly]; dual-registered 248/tcp + 248/udp with identical row data [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Range class
well-known (0–1023) [Confirmed] — port number falls in the IANA well-known range by definition
Prevalence
nmap-services scan-frequency probability ≈0.000013 for tcp, ≈0.000511 for udp — rarely found open in the wild [Likely] — https://github.com/nmap/nmap (nmap-services file)
Related ports
354/tcp (bh611) shares the identical IANA contact [John_Kelly], suggesting these may be a small batch of individual registrations rather than a widely adopted protocol family — an inference from cross-referencing two obscure registry rows, not an IANA statement [Likely] — https://www.connected.app/ports/354 ; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv

Primary use

Unknown/undocumented — the registered name has no RFC, spec, or vendor documentation describing an actual protocol

[Confirmed absence of documentation] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv

Other/unofficial uses

none identified in current or historical software

[Likely] — no citation found for any implementation

Security implications

no confirmed malware association from the more conservative source; a separate, uncited, templated-language source claims port 248 has been abused for C2, but gives no evidence and conflicts with the other source — treated as unverified, not stated as fact [Likely for "no confirmed malware"; Unknown for the C2 claim] — https://www.auditmypc.com/tcp-port-248.asp ; https://www.connected.app/ports/248

Typically seen on

no known legitimate deployment; an open 248/tcp is an anomaly worth investigating rather than an expected service [Likely]

Analyst note
treat an open 248/tcp as unexplained; verify with a banner grab rather than assuming either the "clean" or "malware" secondary-source claims.
[ 02 ] — Context

About port 248/udp.

Updated  ·  Confidence: Low

Port 248/udp is registered with IANA under the service name bhfhs, with the description field also reading "bhfhs" — an unusual case where the registry does not expand or explain the acronym itself. The assignee and contact are both listed as [John_Kelly], and the port is dual-registered: an essentially identical entry exists for 248/tcp, carrying the same service name, description, and contact, with no other fields populated on either row — no registration date, no modification date, and no formal RFC or reference. This blank pattern is typical of IANA's older, informally-assigned port registrations from the early Internet era, where an individual or small organization requested a service name without publishing a companion specification. Independent web research turned up no documentation clarifying what "bhfhs" stands for, and no mainstream application, protocol stack, or vendor product known to use 248/udp in practice today. No CVE, malware family, or notable scanning/exposure report ties specifically to this port; a general-purpose port-lookup aggregator returns only boilerplate "not currently flagged" status rather than incident-specific evidence, and the port does not appear on commonly-cited high-scan-volume lists. Taken together, 248/udp reads as a dormant, low-prevalence legacy IANA assignment with no confirmed real-world deployment, rather than an actively used or security-relevant service today.

IANA assignment
service name bhfhs, description "bhfhs", assignee/contact [John_Kelly] [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 574); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Dual registration
248/tcp carries an identical service name/description/contact, all other fields also blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 573)
Registration date / modification date
blank in the registry (confirmed blank, not researched-and-lost) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
IANA reference / RFC
blank — no RFC or specification cited in the registry; none invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]

Protocol meaning / expansion

IANA does not expand the acronym; one secondary mirror hinted at a possible private/vendor contact email, uncorroborated by IANA itself

[Unknown] — http://www.wjsend.de/Port_assignments

Common software / real-world usage

none identified in this research pass

[Unknown] — https://www.speedguide.net/port.php?port=248, https://tcp-udp-ports.com/port-248.htm
Security exposure
no CVE or malware association found; generic "not flagged" boilerplate from a port-lookup aggregator, not incident-specific evidence; port absent from high-scan-volume lists [Likely] — https://www.auditmypc.com/udp-port-248.asp
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
bhfhs UDP 0.05%
bhfhs TCP 0.00%
IANA name
bhfhs
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.