352
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No standardized protocol is defined for this port; the only two IANA registrations are legacy, non-RFC entries with no known deployment, so a live listener here is atypical and should be treated as anomalous rather than expected traffic.
- // analyst note
- absent independent documentation of a real protocol, treat a live listener on 352/tcp as unusual and worth manual investigation rather than assuming a known service.
- // if you see it open
- No known CVE, malware, or threat association was found for port 352. The port has no standardized service, so an open listener is atypical; treat as anomalous and investigate rather than assume a known application. Search-tool constraints in this pass prevented broader confirmation.
About port 352/tcp.
Port 352/tcp carries no standardized service — IANA's registry lists two competing legacy entries, dtag-ste-sb and bhoedap4, neither of which documents an actual protocol — so this port should not be treated as belonging on the public internet, and any live listener is an anomaly worth investigating rather than an expected service.
The IANA Service Name and Transport Protocol Port Number Registry dual-registers both names across TCP and UDP. The first, dtag-ste-sb, carries only the bare description "DTAG" and is assigned to Ruediger_Wald, who is also the listed contact. The second, bhoedap4, carries the bare description "bhoedap4" itself and is assigned to John_Kelly, also the listed contact; it is recorded as an unassigned-but-widespread use dating to 5/21/97.
Both entries have a blank IANA reference field — no RFC or formal specification is cited for either name, and no registration date is listed for either. This pattern is consistent with the registry's oldest, informally-added entries rather than a standards-track assignment.
No public documentation of an actual wire protocol, vendor implementation, or deployed software could be found for either dtag-ste-sb or bhoedap4 in this research pass. General web search was unavailable (session search budget exhausted), and targeted fetches to community port-lookup sites (SpeedGuide, adminsub.net) failed with HTTP 403 and HTTP 522 respectively; Wikipedia's port list does not mention port 352 at all.
No CVE, malware family, or known-backdoor association is documented for port 352 in the sources that were reachable. Given the port has no standardized service and only two obscure legacy registrations, an open 352/tcp should be treated as anomalous — investigate it as a possible legacy service, misconfiguration, or non-standard application rather than assuming a known protocol.
- Exposure
- No standardized service is defined for this port, so a live listener is atypical and should be treated as anomalous rather than expected internet-facing or restricted-service traffic [Likely] — IANA Service Name and Transport Protocol Port Number Registry.
- Legacy registrations
- Two competing IANA entries share the port —
dtag-ste-sb(description "DTAG", assignee/contact Ruediger_Wald) andbhoedap4(description "bhoedap4", recorded as an unassigned-but-widespread use since 5/21/97, assignee/contact John_Kelly) — neither documents an actual wire protocol[Confirmed] — IANA service-names-port-numbers registry. - Known malware/CVE
- None found in this research pass; no CVE or malware family is documented as using port 352 [Unknown].
- Analyst guidance
- Treat an unexpected open 352/tcp as worth investigating for a legacy or custom service, or a misconfiguration, rather than assuming a known application is behind it.
- IANA assignment
- two dual TCP/UDP entries —
dtag-ste-sb(description "DTAG", assignee/contact Ruediger_Wald) andbhoedap4(description "bhoedap4", assignee/contact John_Kelly, recorded as unassigned-but-widespread since 5/21/97); both Reference fields blank[Confirmed] — IANA Service Name and Transport Protocol Port Number Registry - Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — no scan-prevalence data (e.g. nmap-services) was available in this research pass [Unknown]
- Related ports
- no clearly related cluster identified in this pass [Unknown]
Primary use
no standardized application protocol is documented; both IANA entries appear to be legacy/informal registrations without published protocol specs
Other/unofficial uses
none documented in reachable sources this pass [Unknown]
Security implications
no known CVE, malware, or threat association found; an open port 352 has no standard justification and should be investigated as anomalous [Unknown/Likely]
Typically seen on
no confirmed hosts or software; historically associated only with the two legacy IANA registrants (Ruediger Wald for dtag-ste-sb, John Kelly for bhoedap4) [Unknown]
- Analyst note
- absent independent documentation of a real protocol, treat a live listener on 352/tcp as unusual and worth manual investigation rather than assuming a known service.
About port 352/udp.
Port 352/udp carries no single well-defined service. IANA's registry lists two separate, unrelated legacy name assignments for this port number rather than one canonical protocol, and no RFC exists for either — so it should not be assumed to run any specific contemporary application, and should generally not be expected open on a public-facing host.
IANA's Service Name and Transport Protocol Port Number Registry shows two rows sharing port 352, both registered for tcp and udp: "dtag-ste-sb," described only as "DTAG" with assignee Ruediger Wald and a blank reference field, and "bhoedap4," described only as "bhoedap4" with assignee John Kelly.
The bhoedap4 entry carries an IANA administrative note stating it "records an unassigned but widespread use (added 5/21/97)" — language IANA uses for ports observed in the wild before any formal assignment or specification, not for a documented protocol.
Neither entry cites an RFC or other reference specification, and no further protocol detail (packet format, purpose beyond the bare name) is available in the registry. Community-sourced usage research (vendor docs, forums, blog write-ups) was not completed in this pass because the session's web-search budget was exhausted first, so current-day application attribution and internet-scanning prevalence for this specific port are Unknown rather than confirmed absent.
Given the blank protocol documentation and the "unassigned but widespread use" language on one of the two entries, this research surfaced no legitimate, well-known contemporary use for port 352. It should not be assumed safe or expected on a modern network, and any traffic seen on it warrants investigation rather than default trust.
- Exposure
- No documented legitimate protocol or contemporary application justifies routine exposure; any observed traffic should be treated as unidentified/anomalous until investigated. [Likely]
- Historical basis
- Two unrelated legacy IANA names (dtag-ste-sb, bhoedap4) share this port number with a blank RFC reference and an "unassigned but widespread use" note — a sign of ad hoc registry history rather than an actively maintained protocol. [Confirmed] — IANA registry
- Scan/prevalence data
- Not verified this pass (tool budget exhausted before scan-prevalence research could run). [Unknown]
- Recommendation
- Investigate rather than assume known software is responsible; re-check community sources in a follow-up pass for current application attribution before relying on this entry for that purpose. [Likely]
- IANA assignment
- dual legacy registration —
dtag-ste-sb("DTAG," assignee Ruediger_Wald, blank reference) andbhoedap4("bhoedap4," assignee John_Kelly, note: "This entry records an unassigned but widespread use (added 5/21/97)"); both registered for tcp and udp[Confirmed] — IANA Service Names and Port Numbers Registry - Range class
- well-known (0–1023)
- Prevalence
- Unknown / not verified this pass (WebSearch budget exhausted before scan-prevalence check) [Unknown]
- Related ports
- neighboring legacy dual-registered low-numbered ports in the same IANA range [Unknown]
Primary use
Unknown — no protocol specification exists for either registered name [Unknown]
Other/unofficial uses
none verified this pass [Unknown]
Security implications
no known CVEs found for this port; unidentified/anomalous traffic warrants investigation given the absence of a documented protocol [Likely]
Typically seen on
Unknown / not verified [Unknown]
- Analyst note
- Treat an open 352/udp as anomalous given the blank RFC reference and the "unassigned but widespread use" IANA note for one of the two registered names; do not assume it belongs to a specific known application without further evidence.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dtag-ste-sb | UDP | DTAG, or bhoedap4 | 0.06% |
| dtag-ste-sb | TCP | DTAG, or bhoedap4 | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.