Network port detail · UDP/TCP

357

Bhevent
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No documented legitimate application uses this IANA-registered but functionally undocumented service, and it has historically appeared in generic legacy Trojan-signature port lists, so an open 357/tcp warrants investigation rather than being assumed benign.
// analyst note
an open port 357/tcp has no well-documented legitimate purpose; treat as an anomaly to investigate rather than a known-benign service.
// if you see it open
No CVE or active-campaign report was found tied to port 357. AuditMyPC's port-scan reference site lists port 357 (tcp/udp) as historically appearing in some legacy antivirus/port-scanner Trojan-signature lists, a generic and dated flag attached to many older ports; its own current classification for TCP 357 reads 'Virus / Trojan: No'. No documented legitimate application was found, so an unexpected listener here should be investigated rather than assumed benign.
[ 01 ] — Context

About port 357/tcp.

Updated  ·  Confidence: Low

Port 357/tcp is IANA-registered under the service name bhevent, but no documentation exists explaining what the service actually does, so it should not be expected as a routine public-internet listener and any traffic on it deserves closer investigation rather than assumption.

The IANA Service Name and Transport Protocol Port Number Registry lists 357 as dual-registered on TCP and UDP for bhevent, with contact/assignee [John_Kelly] and a blank reference field — no RFC or specification is cited. Port-lookup aggregator sites (SpeedGuide, adminsub.net, t1shopper) simply mirror this same bare IANA label without adding functional detail.

No vendor documentation, product page, or community report was found identifying software that actually generates traffic on 357/tcp. This pass found no credible, citable application to list, so common applications are left empty rather than guessed.

One port-scan reference site (AuditMyPC) notes that port 357 (both tcp and udp) appears in some legacy port-scanning tools' malware-signature lists as historically associated with Trojan/virus activity — a generic, dated disclaimer attached to many older ports rather than a specific incident report. AuditMyPC's own current classification for TCP 357 reads "Virus / Trojan: No," and no CVE or active-campaign report was found tying malware to this port.

IANA assignment
bhevent — no description beyond the service name; contact [John_Kelly]; dual-registered 357/tcp + 357/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-700
Range class
well-known (0–1023) [Confirmed]
Prevalence
no scan-frequency or telemetry data surfaced in this pass [Unknown]
Related ports
no closely related port cluster identified in this pass [Unknown]

Primary use

Unknown — no vendor documentation, RFC, or product reference explains what bhevent does

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv

Other/unofficial uses

none credibly sourced [Unknown]

Security implications

no CVE or active-campaign report found; historically listed in some legacy port-scan tools' generic Trojan/virus signature references, currently classified non-malicious by that same source

[Likely] — https://www.auditmypc.com/tcp-port-357.asp

Typically seen on

Unknown — no evidence of which hosts or software commonly expose this port [Unknown]

Analyst note
an open port 357/tcp has no well-documented legitimate purpose; treat as an anomaly to investigate rather than a known-benign service.
[ 02 ] — Context

About port 357/udp.

Updated  ·  Confidence: Low

Port 357/udp carries an IANA-registered service name, "bhevent," but the registry entry supplies only the name and a registrant contact — no description, RFC, or specification exists — so no legitimate application has been identified, and a host with 357/udp open to the public internet should be treated as anomalous and investigated rather than assumed to be running a known service.

IANA's service-names-port-numbers registry lists bhevent as dual-registered on both 357/tcp and 357/udp, assigned to individual registrant John Kelly ([John_Kelly]), with the Reference field left blank. A blank reference alongside an individual (rather than organizational) registrant is typical of older First-Come-First-Served IANA assignments where a name was reserved but no protocol was ever published or widely deployed.

No vendor documentation, product manual, protocol write-up, or community report was found describing what bhevent actually does or naming software that generates traffic on this port. Secondary port-lookup aggregator sites (SpeedGuide, adminsub.net, auditmypc.com) simply mirror the bare IANA label without adding vendor identification or usage evidence, and no malware family, P2P client, or game-server documentation references port 357.

IANA assignment
bhevent — no free-text description; reference blank; assignee John Kelly ([John_Kelly]); dual-registered 357/tcp + 357/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
Unknown — no nmap-services open-frequency figure or scan-prevalence statistic was located for 357/udp in this pass [Unknown]
Related ports
none identified as directly related to bhevent [Unknown]

Primary use

Unknown — IANA publishes no protocol description, specification, or RFC for bhevent

[Unknown] — IANA registry

Other/unofficial uses

none found; no vendor documentation or community report identifies software using this port [Unknown]

Security implications

no confirmed malware/trojan association; a single uncorroborated aggregator page (auditmypc.com) states "no" trojan association; the registry's blank description/RFC is consistent with an inactive or never-widely-deployed assignment

[Unknown/Likely] — auditmypc.com, IANA

Typically seen on

no known typical deployment identified; unexpected on any host absent independent confirmation [Unknown]

Analyst note
An open 357/udp with no identifiable legitimate application should be treated as anomalous and worth investigating, not assumed benign.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
bhevent UDP 0.05%
bhevent TCP 0.00%
IANA name
bhevent
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.