Network port detail · UDP/TCP

365

Dtk
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — 365/tcp is registered to a niche honeypot/deception toolkit (DTK) rather than a mainstream production service, so a live listener is essentially never a normal legitimate service and should be investigated as a possible decoy or anomaly.
// analyst note
A responsive port 365 is uncommon and most plausibly either a deliberate honeypot or an artifact of broad scanning — investigate rather than assume legitimacy.
// if you see it open
Not a mainstream production service; a live listener is most plausibly an intentional honeypot/decoy deployment or incidental exposure caught by broad port scanning. No CVEs or malware/trojan-port-list entries naming port 365 were found in sources reviewed this pass (absence not confirmed as exhaustive). IANA Reference field is blank and no registration date is published.
[ 01 ] — Context

About port 365/tcp.

Updated  ·  Confidence: Medium

Port 365/tcp is registered to DTK (Deception Toolkit), a honeypot/deception framework rather than a mainstream production service, so a live listener should generally be either an intentional decoy or treated as an anomaly worth investigating — not exposed as ordinary infrastructure.

IANA registers both 365/tcp and 365/udp under the service name dtk, description "DTK," with assignee Fred Cohen and a blank Reference field (no RFC is cited). DTK is an early (1997-era) honeypot toolkit created by security researcher Fred Cohen that emulates vulnerable services to lure, log, and study attacker or scanner activity.

No registration date is recorded in the IANA registry data retrieved, so that field is left Unknown rather than fabricated. The port is not tied to any mainstream well-known service (no HTTP, mail, database, or similar role), and no CVEs or malware/trojan-port associations were found for it in the sources reviewed this pass.

Community-sourced usage data is thin: DTK's own project domain (dtk.org) has lapsed and now resolves to a domain-parking page, Wikipedia has no entry for the port or DTK, and secondary port-reference sites (speedguide.net, adminsub.net) returned errors when fetched. As a result, no specific "commonly seen" applications beyond DTK itself could be verified, and that gap is recorded honestly rather than guessed.

IANA assignment
dtk — "DTK"; reference (blank — no RFC cited); assignee Fred Cohen; dual-registered 365/tcp + 365/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
no nmap-services or scan-prevalence figures were available from the research angles run this pass [Unknown]
Related ports
none specifically documented as related; compare against mainstream well-known ports in the same 0–1023 range for baseline expectations [Unknown]

Primary use

Deception Toolkit (DTK), an early honeypot/deception framework by Fred Cohen that emulates vulnerable services to attract and log attacker/scanner activity [Likely] — IANA registry entry (protocol behavior inferred from the registry description and DTK's documented purpose, not a dedicated RFC)

Other/unofficial uses

none verifiably documented; DTK's own domain (dtk.org) has lapsed to a parked-domain page and no other applications could be confirmed on this port [Unknown]

Security implications

essentially a niche security-research/decoy port rather than a production service; no CVEs or malware associations found this pass

[Unknown/Likely] — see Security section

Typically seen on

hosts intentionally running DTK as a honeypot/deception deployment; otherwise not expected in normal production traffic [Likely]

Analyst note
A responsive port 365 is uncommon and most plausibly either a deliberate honeypot or an artifact of broad scanning — investigate rather than assume legitimacy.
[ 02 ] — Context

About port 365/udp.

Updated  ·  Confidence: Medium

Port 365/udp carries no mainstream application traffic; it is IANA-registered to Fred Cohen's Deception Toolkit (DTK), a legacy honeypot/deception framework, and should essentially never be found open on production internet-facing infrastructure.

IANA lists 365 as dtk — "DTK" — dual-registered on both 365/tcp and 365/udp, with assignee and contact "[Fred_Cohen]" and a blank Reference field (no RFC was ever published for it). No registration date is present in the registry.

DTK's own project documentation designates port 365 as the toolkit's fixed "deception port": a machine can expose or intentionally suppress it to signal that DTK-style deception defenses (simulated vulnerable services meant to waste attacker effort and aid detection) may be running. This is a niche, largely historical late-1990s security-research use rather than a mainstream protocol or service.

No third-party or community-sourced report of any other software, game client, or malware using UDP/365 was found in this pass, and no independent scan-telemetry source (e.g., a honeypot-tracking or scan-observatory report) confirming active internet scanning of the port turned up either — those dimensions are Unknown rather than assumed.

IANA assignment
dtk — "DTK"; dual-registered 365/tcp + 365/udp; assignee/contact [Fred_Cohen]; Reference field blank (no RFC) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-724
Range class
well-known (0–1023) [Confirmed]
Prevalence
no nmap-services or telemetry figure surfaced for this port in this pass [Unknown]
Related ports
365/tcp (same dtk dual registration)

Primary use

fixed "deception port" for Fred Cohen's Deception Toolkit (DTK), a honeypot/deception framework

[Confirmed] — https://all.net/dtk/dtk.html

Other/unofficial uses

none identified — no other software found using UDP/365

[Unknown] — search coverage documented in angle notes

Security implications

exposure signals deception-defense presence per DTK's own design rationale; no independent scan or malware-association data found

[Likely] — https://all.net/dtk/dtk.html

Typically seen on

legacy/niche DTK honeypot deployments; otherwise an anomaly [Likely]

Analyst note
An open port 365/udp is rare and, per the tool's own documentation, most plausibly a DTK deception signal rather than a genuine service — investigate rather than assume routine traffic.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dtk UDP Deception Tool Kit (www.all.net) 0.04%
dtk TCP Deception Tool Kit (www.all.net) 0.00%
IANA name
dtk
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.