Network port detail · UDP/TCP

365

Dtk
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — 365/tcp is registered to a niche honeypot/deception toolkit (DTK) rather than a mainstream production service, so a live listener is essentially never a normal legitimate service and should be investigated as a possible decoy or anomaly.
// analyst note
A responsive port 365 is uncommon and most plausibly either a deliberate honeypot or an artifact of broad scanning — investigate rather than assume legitimacy.
// if you see it open
Not a mainstream production service; a live listener is most plausibly an intentional honeypot/decoy deployment or incidental exposure caught by broad port scanning. No CVEs or malware/trojan-port-list entries naming port 365 were found in sources reviewed this pass (absence not confirmed as exhaustive). IANA Reference field is blank and no registration date is published.
[ 01 ] — Context

About port 365/tcp.

Updated  ·  Confidence: Medium  ·  2 sources  ·  How this page is checked

Port 365/tcp is registered to DTK (Deception Toolkit), a honeypot/deception framework rather than a mainstream production service, so a live listener should generally be either an intentional decoy or treated as an anomaly worth investigating — not exposed as ordinary infrastructure.

IANA registers both 365/tcp and 365/udp under the service name dtk, description "DTK," with assignee Fred Cohen and a blank Reference field (no RFC is cited). DTK is an early (1997-era) honeypot toolkit created by security researcher Fred Cohen that emulates vulnerable services to lure, log, and study attacker or scanner activity.

No registration date is recorded in the IANA registry data retrieved, so that field is left Unknown rather than fabricated. The port is not tied to any mainstream well-known service (no HTTP, mail, database, or similar role), and no CVEs or malware/trojan-port associations were found for it in the sources reviewed this pass.

Community-sourced usage data is thin: DTK's own project domain (dtk.org) has lapsed and now resolves to a domain-parking page, Wikipedia has no entry for the port or DTK, and secondary port-reference sites (speedguide.net, adminsub.net) returned errors when fetched. As a result, no specific "commonly seen" applications beyond DTK itself could be verified, and that gap is recorded honestly rather than guessed.

Exposure
DTK is a deception/honeypot tool, not a production service — a real-world listener on 365/tcp is most plausibly either a deliberate honeypot deployment or incidental exposure caught by broad internet port scans, not evidence of a mainstream application.
Registry gaps
IANA's Reference field is blank and no registration date is published; both are left Unknown rather than invented, per registry data reviewed [Confirmed] — IANA Service Names and Transport Protocol Port Number Registry.
No known CVEs
No CVEs or malware/trojan-port-list entries specifically naming port 365 were found in the sources accessible this pass; this should be read as "not found this pass," not as a clean bill of health.
Analyst note
Treat an unexpected open 365/tcp as worth investigating — either a knowingly deployed decoy/honeypot or an anomaly — rather than assuming a benign mainstream service.
IANA assignment
dtk — "DTK"; reference (blank — no RFC cited); assignee Fred Cohen; dual-registered 365/tcp + 365/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
no nmap-services or scan-prevalence figures were available from the research angles run this pass [Unknown]
Related ports
none specifically documented as related; compare against mainstream well-known ports in the same 0–1023 range for baseline expectations [Unknown]

Primary use

Deception Toolkit (DTK), an early honeypot/deception framework by Fred Cohen that emulates vulnerable services to attract and log attacker/scanner activity [Likely] — IANA registry entry (protocol behavior inferred from the registry description and DTK's documented purpose, not a dedicated RFC)

Other/unofficial uses

none verifiably documented; DTK's own domain (dtk.org) has lapsed to a parked-domain page and no other applications could be confirmed on this port [Unknown]

Security implications

essentially a niche security-research/decoy port rather than a production service; no CVEs or malware associations found this pass

[Unknown/Likely] — see Security section

Typically seen on

hosts intentionally running DTK as a honeypot/deception deployment; otherwise not expected in normal production traffic [Likely]

Analyst note
A responsive port 365 is uncommon and most plausibly either a deliberate honeypot or an artifact of broad scanning — investigate rather than assume legitimacy.
[ 02 ] — Context

About port 365/udp.

Updated  ·  Confidence: Medium  ·  3 sources  ·  How this page is checked

Port 365/udp carries no mainstream application traffic; it is IANA-registered to Fred Cohen's Deception Toolkit (DTK), a legacy honeypot/deception framework, and should essentially never be found open on production internet-facing infrastructure.

IANA lists 365 as dtk — "DTK" — dual-registered on both 365/tcp and 365/udp, with assignee and contact "[Fred_Cohen]" and a blank Reference field (no RFC was ever published for it). No registration date is present in the registry.

DTK's own project documentation designates port 365 as the toolkit's fixed "deception port": a machine can expose or intentionally suppress it to signal that DTK-style deception defenses (simulated vulnerable services meant to waste attacker effort and aid detection) may be running. This is a niche, largely historical late-1990s security-research use rather than a mainstream protocol or service.

No third-party or community-sourced report of any other software, game client, or malware using UDP/365 was found in this pass, and no independent scan-telemetry source (e.g., a honeypot-tracking or scan-observatory report) confirming active internet scanning of the port turned up either — those dimensions are Unknown rather than assumed.

Exposure
Not a service meant for public reach; a live host that intentionally responds on 365/udp is signaling deception-toolkit presence, per DTK's own design rationale, not offering a real network service.
Recon value
DTK's authors themselves note that an exposed port 365 tips off attackers who want to avoid deceptive defenses, so its presence (or deliberate suppression) is itself an intelligence signal in either direction.
Third-party confirmation
No independent scan-telemetry or malware-association report for UDP/365 was found in this pass — treat any observed traffic as unusual and worth investigating rather than routine.
IANA assignment
dtk — "DTK"; dual-registered 365/tcp + 365/udp; assignee/contact [Fred_Cohen]; Reference field blank (no RFC) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-724
Range class
well-known (0–1023) [Confirmed]
Prevalence
no nmap-services or telemetry figure surfaced for this port in this pass [Unknown]
Related ports
365/tcp (same dtk dual registration)

Primary use

fixed "deception port" for Fred Cohen's Deception Toolkit (DTK), a honeypot/deception framework

[Confirmed] — https://all.net/dtk/dtk.html

Other/unofficial uses

none identified — no other software found using UDP/365

[Unknown] — search coverage documented in angle notes

Security implications

exposure signals deception-defense presence per DTK's own design rationale; no independent scan or malware-association data found

[Likely] — https://all.net/dtk/dtk.html

Typically seen on

legacy/niche DTK honeypot deployments; otherwise an anomaly [Likely]

Analyst note
An open port 365/udp is rare and, per the tool's own documentation, most plausibly a DTK deception signal rather than a genuine service — investigate rather than assume routine traffic.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dtk UDP Deception Tool Kit (www.all.net) 0.04%
dtk TCP Deception Tool Kit (www.all.net) 0.00%
IANA name
dtk
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.