Network port detail · UDP/TCP

377

tnETOS
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
A secondary port-lookup aggregator (AuditMyPC) flags TCP 377 as a port that a Trojan or Virus has used to communicate in the past, but marks current trojan/virus status as 'No' and provides no malware name, date, or incident detail. No CVE, honeypot report, or scanning-trend writeup for this port was found. Treat as low-confidence and unattributed rather than a documented threat.
// analyst note
Treat an open 377/tcp as undocumented and worth investigating; no confirmed legitimate current use was found in this pass.
[ 01 ] — Context

About port 377/tcp.

Updated  ·  Confidence: Low

Port 377/tcp is IANA-registered under the name tnETOS with description "NEC Corporation," but no protocol description, RFC, or vendor document defines what it actually does — treat any host answering on this port as undocumented rather than assume it belongs on the public internet.

The IANA registry lists the service name tnETOS with description "NEC Corporation" for both 377/tcp and 377/udp (dual registration); the Assignee, Contact, and Reference columns are blank. No RFC or NEC vendor specification describing the protocol's function was located. The name plausibly ties to NEC's "ETOS" terminal/network environment via a telnet-style ("tn") prefix, but that is an inference from the name alone, not a confirmed fact, and no source substantiates it.

No community sightings, forum threads, or client documentation naming software that generates traffic on port 377 were found; searches surfaced only generic port-directory pages mirroring the bare IANA entry. One secondary aggregator (AuditMyPC) flags TCP 377 as a port historically used by "a Trojan or Virus" but marks current trojan/virus status as "No" and provides no malware name, date, or incident detail — a low-confidence, unattributed claim rather than a documented threat.

Given the near-total absence of public documentation, an analyst encountering an open 377/tcp should treat it as an anomaly worth investigating rather than a recognized legitimate service, and should not assume it is safe to expose.

IANA assignment
tnETOS — description "NEC Corporation"; assignee and contact blank; reference field blank; dual-registered 377/tcp + 377/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 747-748)
Range class
well-known (0–1023) [Confirmed]
Prevalence
Not established in this research pass — no nmap-services open-frequency figure was located for 377/tcp [Unknown]
Related ports
None confidently identified [Unknown]

Primary use

Unknown — IANA publishes only the bare service name; no NEC vendor documentation describing the protocol's actual function was found

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

None identified in public sources [Unknown]

Security implications

AuditMyPC lists TCP 377 as historically flagged for trojan/virus communication, current status "No," with no malware name, date, or incident detail — unattributed and low-confidence

[Likely] — https://www.auditmypc.com/tcp-port-377.asp

Typically seen on

Unknown — no confirmed host or software context identified [Unknown]

Analyst note
Treat an open 377/tcp as undocumented and worth investigating; no confirmed legitimate current use was found in this pass.
[ 02 ] — Context

About port 377/udp.

Updated  ·  Confidence: Low

Port 377/udp is registered with IANA under the service name tnETOS with description "NEC Corporation," but no protocol description, RFC, or vendor specification could be independently verified, so what actually runs on the wire is Unknown — it should not be assumed safe to expose to the public internet.

The IANA registry entry lists the service name tnETOS and description "NEC Corporation"; the assignee, contact, registration date, and reference fields are all blank, and the port is dual-registered on both 377/tcp and 377/udp under the same tnETOS name and the same "NEC Corporation" description. No RFC backs the assignment.

Third-party port-lookup mirrors (SpeedGuide, adminsub.net) repeat the same tnETOS/NEC Corporation attribution, which corroborates the registry entry but does not add any protocol detail. The cached IANA registry is the canonical source consulted for this entry and confirms the service name [Confirmed].

A handful of older, generic "trojan port list" compilations (auditmypc.com, chebucto.ns.ca) flag UDP port 377 as having been historically associated with unspecified trojan or virus activity. None names a specific malware family, gives a date, or describes a mechanism — this reads as decade-old port-list folklore rather than current threat intelligence, and is presented here only as a hedged historical note.

No credible source ties any specific software, game client, or clustering/queueing product to traffic on this port; a guess connecting it to NQS-style batch-queue systems was checked and found no supporting source, so that association is omitted rather than asserted.

IANA assignment
tnETOS — description "NEC Corporation"; reference (blank — no RFC cited); assignee and contact blank; dual-registered 377/tcp + 377/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (IANA registry cache)
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 377/udp ≈ 0.000725 — very low (roughly 7 in 10,000 scanned hosts in the nmap-services sample) [Likely] — nmap-services dataset
Related ports
377/tcp (same tnETOS registration, dual-protocol) [Confirmed]

Primary use

Unknown — no protocol specification, RFC, or vendor writeup for tnETOS was found [Unknown]

Other/unofficial uses

none credibly identified [Unknown]

Security implications

no dated incidents or named malware; only generic, undated "trojan port list" mentions exist for UDP 377

[Likely] — auditmypc.com, chebucto.ns.ca

Typically seen on

Unknown; no host or software context beyond the bare "NEC Corporation" registry description is attested [Unknown]

Analyst note
Treat an open 377/udp as unidentified until confirmed against the host; the registered name alone gives no operational detail, and legacy trojan-list flags are folklore-tier, not current threat intel.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
tnETOS UDP NEC Corporation 0.07%
tnETOS TCP NEC Corporation 0.00%
IANA name
tnETOS
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.