358
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No documented protocol or real-world deployment exists for the 'shrinkwrap' service name, so a listener on 358/tcp has no legitimate expected use and should be treated as anomalous if observed.
- // analyst note
- An open port 358 has no documented legitimate service behind it; treat as anomalous and investigate rather than assume a known application.
- // if you see it open
- No confirmed malware or trojan association was found. auditmypc.com marks the port 'Virus/Trojan: No,' though that note is boilerplate text shared across its port-database pages rather than evidence specific to 358. The absence of any documented protocol or deployment means a listener has no expected legitimate use, so it should be treated as anomalous if observed.
About port 358/tcp.
Port 358/tcp carries no documented service. IANA registers the name shrinkwrap for both TCP and UDP, but no protocol specification, vendor implementation, or real-world sighting has surfaced, so there is no basis for exposing it to the public internet.
The IANA Service Names and Port Numbers registry lists 358/tcp and 358/udp under the name "shrinkwrap," with a one-word description and no RFC or reference document. The registered contact is [Bill_Simpson]; no registration or modification date is published for this entry.
Third-party port-database aggregators (SpeedGuide, auditmypc.com, tcp-udp-ports.com) merely restate the IANA "Shrinkwrap" label. None of them, nor any vendor documentation, blog post, or forum thread found during research, identifies a specific application, game, or service that actually uses port 358 in practice.
Given the bare registration and the absence of any deployment evidence, an analyst encountering traffic on 358/tcp should not assume it maps to any known software family. The safest interpretation is an unused, custom, or anomalous listener rather than a recognizable standard service.
- IANA assignment
shrinkwrap— "Shrinkwrap"; reference (blank — no RFC cited); assignee/contact[Bill_Simpson]; dual-registered 358/tcp + 358/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-702- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — not covered by the researched nmap-services data for this entry [Unknown]
- Related ports
- nearby registered ports in the 350–370 range (not individually researched in this pass)
Primary use
Unknown — no protocol specification or documentation exists beyond the bare IANA name registration
Other/unofficial uses
none credibly sourced; no vendor docs, blog posts, or forum/support threads document software using this port
Security implications
no confirmed malware/trojan association; auditmypc.com marks "Virus/Trojan: No" but the disclaimer text is templated across its port pages, not incident-specific
Typically seen on
Unknown — no real-world sightings were found during research [Unknown]
- Analyst note
- An open port 358 has no documented legitimate service behind it; treat as anomalous and investigate rather than assume a known application.
About port 358/udp.
Port 358/udp is registered with IANA under the service name shrinkwrap, but no RFC, protocol specification, or documented software implementation exists for it; the port carries no confirmed traffic pattern, and any UDP packets observed on 358 should be treated as unexplained rather than assumed to belong to a legitimate, recognized service.
The IANA Service Name and Transport Protocol Port Number Registry lists 358 as shrinkwrap on both tcp and udp, assigned to Bill Simpson, with a blank Reference column — the registry documents only the name and assignee, not a specification. No RFC or informal draft describing a "shrinkwrap" wire protocol has surfaced in this research pass.
Beyond generic port-lookup mirror sites that echo the IANA name back with boilerplate TCP/UDP text, no vendor documentation, blog post, or forum thread describes software actually using 358/udp. A similarly-named "psmond" tool surfaced during research but runs on port 1788 and is unrelated to this entry.
Given the total absence of a protocol spec, known client/server software, or reported abuse, an analyst who observes traffic on 358/udp should treat it as unusual: a custom or private application reusing an otherwise-dormant registered port, a misconfiguration, or a signature worth fingerprinting rather than a recognized service to dismiss.
- IANA assignment
shrinkwrap— "Shrinkwrap"; reference (blank — no RFC cited in IANA registry); assignee Bill Simpson; dual-registered 358/tcp + 358/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — no nmap-services or scanning-prevalence data specific to 358/udp found in this pass [Unknown]
- Related ports
- 358/tcp (dual-registered
shrinkwrapentry, same assignee) [Confirmed] — IANA registry
Primary use
Unknown — no RFC or protocol specification published for "shrinkwrap"; the IANA registry documents only the name and assignee
Other/unofficial uses
None found — no vendor docs, blog posts, or forum threads identify software using 358/udp
Security implications
No CVE, malware, or abuse reporting found specific to 358/udp
Typically seen on
Unknown — no documented deployments [Unknown]
- Analyst note
- The absence of a protocol spec and any observed software makes traffic on 358/udp worth investigating as anomalous rather than routine.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| shrinkwrap | UDP | — | 0.04% |
| shrinkwrap | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.