357
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No documented legitimate application uses this IANA-registered but functionally undocumented service, and it has historically appeared in generic legacy Trojan-signature port lists, so an open 357/tcp warrants investigation rather than being assumed benign.
- // analyst note
- an open port 357/tcp has no well-documented legitimate purpose; treat as an anomaly to investigate rather than a known-benign service.
- // if you see it open
- No CVE or active-campaign report was found tied to port 357. AuditMyPC's port-scan reference site lists port 357 (tcp/udp) as historically appearing in some legacy antivirus/port-scanner Trojan-signature lists, a generic and dated flag attached to many older ports; its own current classification for TCP 357 reads 'Virus / Trojan: No'. No documented legitimate application was found, so an unexpected listener here should be investigated rather than assumed benign.
About port 357/tcp.
Port 357/tcp is IANA-registered under the service name bhevent, but no documentation exists explaining what the service actually does, so it should not be expected as a routine public-internet listener and any traffic on it deserves closer investigation rather than assumption.
The IANA Service Name and Transport Protocol Port Number Registry lists 357 as dual-registered on TCP and UDP for bhevent, with contact/assignee [John_Kelly] and a blank reference field — no RFC or specification is cited. Port-lookup aggregator sites (SpeedGuide, adminsub.net, t1shopper) simply mirror this same bare IANA label without adding functional detail.
No vendor documentation, product page, or community report was found identifying software that actually generates traffic on 357/tcp. This pass found no credible, citable application to list, so common applications are left empty rather than guessed.
One port-scan reference site (AuditMyPC) notes that port 357 (both tcp and udp) appears in some legacy port-scanning tools' malware-signature lists as historically associated with Trojan/virus activity — a generic, dated disclaimer attached to many older ports rather than a specific incident report. AuditMyPC's own current classification for TCP 357 reads "Virus / Trojan: No," and no CVE or active-campaign report was found tying malware to this port.
- IANA assignment
bhevent— no description beyond the service name; contact[John_Kelly]; dual-registered 357/tcp + 357/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-700- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- no scan-frequency or telemetry data surfaced in this pass [Unknown]
- Related ports
- no closely related port cluster identified in this pass [Unknown]
Primary use
Unknown — no vendor documentation, RFC, or product reference explains what bhevent does
Other/unofficial uses
none credibly sourced [Unknown]
Security implications
no CVE or active-campaign report found; historically listed in some legacy port-scan tools' generic Trojan/virus signature references, currently classified non-malicious by that same source
Typically seen on
Unknown — no evidence of which hosts or software commonly expose this port [Unknown]
- Analyst note
- an open port 357/tcp has no well-documented legitimate purpose; treat as an anomaly to investigate rather than a known-benign service.
About port 357/udp.
Port 357/udp carries an IANA-registered service name, "bhevent," but the registry entry supplies only the name and a registrant contact — no description, RFC, or specification exists — so no legitimate application has been identified, and a host with 357/udp open to the public internet should be treated as anomalous and investigated rather than assumed to be running a known service.
IANA's service-names-port-numbers registry lists bhevent as dual-registered on both 357/tcp and 357/udp, assigned to individual registrant John Kelly ([John_Kelly]), with the Reference field left blank. A blank reference alongside an individual (rather than organizational) registrant is typical of older First-Come-First-Served IANA assignments where a name was reserved but no protocol was ever published or widely deployed.
No vendor documentation, product manual, protocol write-up, or community report was found describing what bhevent actually does or naming software that generates traffic on this port. Secondary port-lookup aggregator sites (SpeedGuide, adminsub.net, auditmypc.com) simply mirror the bare IANA label without adding vendor identification or usage evidence, and no malware family, P2P client, or game-server documentation references port 357.
- IANA assignment
bhevent— no free-text description; reference blank; assignee John Kelly ([John_Kelly]); dual-registered 357/tcp + 357/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — no nmap-services open-frequency figure or scan-prevalence statistic was located for 357/udp in this pass [Unknown]
- Related ports
- none identified as directly related to bhevent [Unknown]
Primary use
Unknown — IANA publishes no protocol description, specification, or RFC for bhevent
Other/unofficial uses
none found; no vendor documentation or community report identifies software using this port [Unknown]
Security implications
no confirmed malware/trojan association; a single uncorroborated aggregator page (auditmypc.com) states "no" trojan association; the registry's blank description/RFC is consistent with an inactive or never-widely-deployed assignment
Typically seen on
no known typical deployment identified; unexpected on any host absent independent confirmation [Unknown]
- Analyst note
- An open 357/udp with no identifiable legitimate application should be treated as anomalous and worth investigating, not assumed benign.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| bhevent | UDP | — | 0.05% |
| bhevent | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.