357
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No documented legitimate application uses this IANA-registered but functionally undocumented service, and it has historically appeared in generic legacy Trojan-signature port lists, so an open 357/tcp warrants investigation rather than being assumed benign.
- // analyst note
- an open port 357/tcp has no well-documented legitimate purpose; treat as an anomaly to investigate rather than a known-benign service.
- // if you see it open
- No CVE or active-campaign report was found tied to port 357. AuditMyPC's port-scan reference site lists port 357 (tcp/udp) as historically appearing in some legacy antivirus/port-scanner Trojan-signature lists, a generic and dated flag attached to many older ports; its own current classification for TCP 357 reads 'Virus / Trojan: No'. No documented legitimate application was found, so an unexpected listener here should be investigated rather than assumed benign.
About port 357/tcp.
Port 357/tcp is IANA-registered under the service name bhevent, but no documentation exists explaining what the service actually does, so it should not be expected as a routine public-internet listener and any traffic on it deserves closer investigation rather than assumption.
The IANA Service Name and Transport Protocol Port Number Registry lists 357 as dual-registered on TCP and UDP for bhevent, with contact/assignee [John_Kelly] and a blank reference field — no RFC or specification is cited. Port-lookup aggregator sites (SpeedGuide, adminsub.net, t1shopper) simply mirror this same bare IANA label without adding functional detail.
No vendor documentation, product page, or community report was found identifying software that actually generates traffic on 357/tcp. This pass found no credible, citable application to list, so common applications are left empty rather than guessed.
One port-scan reference site (AuditMyPC) notes that port 357 (both tcp and udp) appears in some legacy port-scanning tools' malware-signature lists as historically associated with Trojan/virus activity — a generic, dated disclaimer attached to many older ports rather than a specific incident report. AuditMyPC's own current classification for TCP 357 reads "Virus / Trojan: No," and no CVE or active-campaign report was found tying malware to this port.
- Exposure
- No documented legitimate widespread use was found for
bhevent; combined with the undocumented registry entry and historical inclusion in generic Trojan-signature port lists, an open 357/tcp is anomalous and worth investigating rather than assuming benign. - Notable CVE
- None found tied to port 357/tcp in this pass.
- Historical malware note
- AuditMyPC's port-scan reference lists port 357 (tcp/udp) as historically flagged in some legacy antivirus/port-scanner Trojan-signature lists, but currently classifies it "Virus / Trojan: No" — https://www.auditmypc.com/tcp-port-357.asp
- Recommendation
- Treat an unexpected listener on 357/tcp as unexplained; there is no known legitimate service to attribute it to with confidence.
- IANA assignment
bhevent— no description beyond the service name; contact[John_Kelly]; dual-registered 357/tcp + 357/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-700- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- no scan-frequency or telemetry data surfaced in this pass [Unknown]
- Related ports
- no closely related port cluster identified in this pass [Unknown]
Primary use
Unknown — no vendor documentation, RFC, or product reference explains what bhevent does
Other/unofficial uses
none credibly sourced [Unknown]
Security implications
no CVE or active-campaign report found; historically listed in some legacy port-scan tools' generic Trojan/virus signature references, currently classified non-malicious by that same source
Typically seen on
Unknown — no evidence of which hosts or software commonly expose this port [Unknown]
- Analyst note
- an open port 357/tcp has no well-documented legitimate purpose; treat as an anomaly to investigate rather than a known-benign service.
About port 357/udp.
Port 357/udp carries an IANA-registered service name, "bhevent," but the registry entry supplies only the name and a registrant contact — no description, RFC, or specification exists — so no legitimate application has been identified, and a host with 357/udp open to the public internet should be treated as anomalous and investigated rather than assumed to be running a known service.
IANA's service-names-port-numbers registry lists bhevent as dual-registered on both 357/tcp and 357/udp, assigned to individual registrant John Kelly ([John_Kelly]), with the Reference field left blank. A blank reference alongside an individual (rather than organizational) registrant is typical of older First-Come-First-Served IANA assignments where a name was reserved but no protocol was ever published or widely deployed.
No vendor documentation, product manual, protocol write-up, or community report was found describing what bhevent actually does or naming software that generates traffic on this port. Secondary port-lookup aggregator sites (SpeedGuide, adminsub.net, auditmypc.com) simply mirror the bare IANA label without adding vendor identification or usage evidence, and no malware family, P2P client, or game-server documentation references port 357.
- Exposure
- No known legitimate application uses 357/udp; an unexpected response on this port is unusual and should be investigated rather than assumed to be a standard service.
- Malware/Trojan claims
- auditmypc.com's UDP-357 page states "Virus / Trojan: No" for this port, but offers no supporting source, and no corroborating AV-vendor or IDS write-up was found either confirming or denying malicious use — treat any trojan association as unverified (https://www.auditmypc.com/udp-port-357.asp).
- Registration gap
- The IANA entry carries no description, RFC, or reference, which is unusual for a well-known-range assignment and consistent with a name that was reserved but never accompanied by a published, deployed protocol (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt).
- Scanning visibility
- No dated scan-prevalence statistic, honeypot report, or mass-scan write-up specifically covering 357/udp was located in this research pass; its visibility in general internet-scanning literature is unknown.
- IANA assignment
bhevent— no free-text description; reference blank; assignee John Kelly ([John_Kelly]); dual-registered 357/tcp + 357/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — no nmap-services open-frequency figure or scan-prevalence statistic was located for 357/udp in this pass [Unknown]
- Related ports
- none identified as directly related to bhevent [Unknown]
Primary use
Unknown — IANA publishes no protocol description, specification, or RFC for bhevent
Other/unofficial uses
none found; no vendor documentation or community report identifies software using this port [Unknown]
Security implications
no confirmed malware/trojan association; a single uncorroborated aggregator page (auditmypc.com) states "no" trojan association; the registry's blank description/RFC is consistent with an inactive or never-widely-deployed assignment
Typically seen on
no known typical deployment identified; unexpected on any host absent independent confirmation [Unknown]
- Analyst note
- An open 357/udp with no identifiable legitimate application should be treated as anomalous and worth investigating, not assumed benign.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| bhevent | UDP | — | 0.05% |
| bhevent | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.