347
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No documented modern application or vendor use of 347/tcp was found and IANA supplies no protocol reference, so an unexpected live listener should be treated as anomalous and investigated rather than assumed to be routine internet-facing or restricted-access traffic; its near-zero nmap-services frequency reinforces this.
- // analyst note
- An unexplained listener on 347/tcp cannot be attributed to any known modern application — verify the bound process directly rather than trusting the "fatserv" label; its near-zero nmap-services frequency makes a genuine response here especially unusual.
- // if you see it open
- No documented CVEs, advisories, or malware associations found for 347/tcp. SANS ISC's port-activity tracker shows only low-level opportunistic scanning (green/low threat level) rather than targeted campaign activity. Given the absence of any modern documented application and a near-zero nmap-services observation frequency, an open port 347 is best treated as a legacy artifact or anomaly rather than expected service traffic.
About port 347/tcp.
Port 347/tcp carries no confirmed, documented service: IANA registers the name fatserv ("Fatmen Server") but supplies no protocol reference, so this port should stay off the public internet and a live listener here deserves direct investigation rather than trust in the registry label.
The IANA Service Name and Transport Protocol Port Number Registry jointly assigns 347/tcp and 347/udp to fatserv, description "Fatmen Server," with a blank Reference field — no RFC or other document backs the assignment — and blank Assignee/Contact and registration-date fields.
No independent source — vendor documentation, blog posts, forum or support threads — describing the "Fatmen" protocol's function, or any modern software generating traffic on this port, could be located, including under the alternate "FATMEN" spelling; this is an honest research gap, not a confirmed absence of usage.
Nmap's nmap-services frequency table, a crowd-sourced measure of how often each port appears across its scanning corpus, lists 347/tcp at 0.000000 — essentially never observed — while 347/udp carries a low but nonzero 0.000708.
SANS Internet Storm Center's live port-activity tracker for port 347 currently shows a green/low threat level, with day-to-day scanning-source activity consistent with routine opportunistic internet-wide scan noise rather than a targeted campaign or evidence of a genuine fatserv deployment.
Given the near-zero nmap frequency, no vendor documentation, and no CVE history, an observed listener on 347/tcp should be treated as a legacy artifact, misconfiguration, or possible decoy rather than expected service traffic — confirm the bound process locally rather than trusting the "fatserv" name.
- IANA assignment
fatserv— "Fatmen Server"; reference (blank — no RFC or document cited); dual-registered 347/tcp + 347/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services frequency
0.000000for 347/tcp (essentially unobserved),0.000708for 347/udp [Confirmed] — https://raw.githubusercontent.com/nmap/nmap/master/nmap-services - Related ports
- 347/udp (identical
fatservregistration, dual-registered) [Confirmed]
Primary use
Unknown — IANA lists only the bare name/description with no protocol specification or RFC
Other/unofficial uses
none identified under either "Fatmen"/"FATMEN" spelling in this research pass [Unknown]
Security implications
no documented CVEs or advisories found; SANS ISC shows only low-level opportunistic scan noise (green/low threat) rather than targeted activity [Confirmed re: scan noise / Unknown re: CVEs] — https://isc.sans.edu/port.html?port=347
Typically seen on
Unknown / no documented modern usage identified [Unknown]
- Analyst note
- An unexplained listener on 347/tcp cannot be attributed to any known modern application — verify the bound process directly rather than trusting the "fatserv" label; its near-zero nmap-services frequency makes a genuine response here especially unusual.
About port 347/udp.
Port 347/udp carries fatserv, IANA's undocumented "Fatmen Server" registration; no protocol specification exists to describe what it does, and the confirmed absence of a real service behind the name means it should not be treated as something to expose to the public internet.
The IANA Service Name and Transport Protocol Port Number Registry lists 347 as dual-registered on TCP and UDP under the same name and description, with a blank Reference column (no RFC cited) and no assignee listed.
A targeted re-check this cycle searched specifically for the exact description string "Fatmen Server" / "FATMEN" and found no protocol write-up, vendor documentation, or community-sourced application tied to it — a confirmed negative, not an exhausted-budget gap.
That same re-check did surface prevalence signal: nmap-services (github.com/nmap/nmap, master branch) records a non-zero open-frequency of 0.000708 for 347/udp (versus 0.000000 for 347/tcp), and SANS ISC's port page logs ongoing low-volume scan-source activity against port 347, with an overall "green" (benign) threat rating and no listed CVEs or comments.
Neither source ties that activity to a specific client, server, or malware family; it reads as generic opportunistic internet scanning rather than confirmed use of a real fatserv protocol. SpeedGuide (403) and adminsub.net (522) remain unreachable across two research cycles. An analyst seeing traffic on 347/udp has no documented legitimate service to compare it against, so any hit is worth investigating as an anomaly rather than assumed benign.
- IANA assignment
fatserv— "Fatmen Server"; reference (blank — no RFC cited); assignee blank; dual-registered 347/tcp + 347/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services frequency 0.000708 for 347/udp (vs. 0.000000 for 347/tcp) [Confirmed] — https://raw.githubusercontent.com/nmap/nmap/master/nmap-services; SANS ISC logs ongoing low-volume scan-source activity, overall rating "green," no listed CVEs [Confirmed] — https://isc.sans.edu/port.html?port=347
- Related ports
- none documented [Unknown]
Primary use
Unknown — a targeted lookup on the exact description string "Fatmen Server"/"FATMEN" surfaced no protocol write-up or vendor documentation [Confirmed negative]
Other/unofficial uses
none found — no community-sourced application sighting confirmed [Confirmed negative]
Security implications
no documented CVEs or malware associations; observed scanning is consistent with generic background internet noise rather than a known exploited service [Confirmed]
Typically seen on
Unknown — no sourced sightings of a specific client or server application [Confirmed negative]
- Analyst note
- This cycle targeted the exact IANA description string plus nmap-services/SANS ISC for prevalence, per the re-research instruction. The protocol gap is now a stated, sourced finding rather than a hedge pending further research.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| fatserv | UDP | Fatmen Server | 0.07% |
| fatserv | TCP | Fatmen Server | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.