Network port detail · UDP/TCP

385

Ibm-app
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No CVEs, exposure/scanning writeups, or vulnerability disclosures found for this port, and no malware association is confirmed for 385/tcp — no named family, sample, or incident. A live listener should still be verified by banner grab or service fingerprint rather than trusted on the strength of the 'ibm-app' registry label.
// analyst note
treat as an obscure, unverified assignment; verify any live listener by banner grab or service fingerprint rather than trusting the "ibm-app" label alone.
[ 01 ] — Context

About port 385/tcp.

Updated  ·  Confidence: Low

Port 385/tcp carries no documented protocol beyond a bare IANA registration for the service name ibm-app ("IBM Application"); no RFC, vendor specification, or product attribution was found, so a live listener here should not be assumed safe and should not be exposed to the public internet without independent verification of what it actually runs.

The IANA registry lists assignee Lisa Tomita, an empty Reference field, and dual registration on both 385/tcp and 385/udp — a pattern typical of 1990s-era enterprise-vendor port reservations that never published an accompanying protocol document. The registration date is not recorded in the source CSV.

No vendor documentation, blog post, or forum/support thread naming a specific IBM product or software using port 385 surfaced during research; secondary port-database aggregator sites only echo the generic IANA label without adding product attribution, so named-application usage is treated as Unknown rather than guessed.

Because neither a protocol spec nor observed traffic data exists, an analyst who finds a live listener on 385/tcp should verify it by banner grab or active service fingerprinting rather than trusting the "ibm-app" label as confirmation of what the service is.

IANA assignment
ibm-app — "IBM Application"; reference (blank); assignee Lisa Tomita; dual-registered 385/tcp + 385/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency 385/tcp ≈ 0.000000 (not observed open); 385/udp ≈ 0.000692 (negligible) [Confirmed] — https://raw.githubusercontent.com/nmap/nmap/master/nmap-services
Related ports
382/tcp + 382/udp (hp-managed-node, HP Performance Data Managed Node), 383/tcp + 383/udp (hp-alarm-mgr, HP Performance Data Alarm Manager), 384/tcp + 384/udp (arns, A Remote Network Server System), 386/tcp + 386/udp (asa, ASA Message Router Object Def.) — other bare IANA enterprise-assignment ports in the 380s range, verified against the registry
[Confirmed] — IANA Service Name and Transport Protocol Port Number Registry

Primary use

unspecified — bare IANA registration only, no RFC or protocol document exists [Confirmed absence of spec]

Other/unofficial uses

Unknown — no vendor docs, blog posts, or forum threads naming a specific application found [Unknown]

Security implications

no confirmed CVEs, exposure/scanning writeups, or vulnerability disclosures found; no malware association is confirmed for 385/tcp [Unknown]

Typically seen on

Unknown

Analyst note
treat as an obscure, unverified assignment; verify any live listener by banner grab or service fingerprint rather than trusting the "ibm-app" label alone.
[ 02 ] — Context

About port 385/udp.

Updated  ·  Confidence: Medium

Port 385/udp is IANA-registered under the generic label "IBM Application" with no public protocol specification on file, so an open 385/udp has no confirmed legitimate internet-facing or internal purpose and should be treated as an anomaly worth investigating rather than a routine service.

The IANA Service Name and Transport Protocol Port Number Registry lists 385/udp as ibm-app, description "IBM Application," assignee Lisa Tomita, with a blank Reference field and no cited RFC. The same name and description are dual-registered on 385/tcp. No registration date is recorded in the source data.

Beyond the bare registry entry, no public documentation, vendor manual, or community source was found describing what the underlying IBM application actually does, what protocol it speaks, or any current software that generates traffic on this port — this appears to be an old, sparsely-documented reservation typical of many decades-old entries in the well-known range. SANS Internet Storm Center tracks background scan visibility on port 385 (tcp/udp) and reported a normal ("green") threat level at check time, consistent with routine broad-range internet scanning rather than a targeted campaign; one community port-lookup aggregator's live page showed no trojan/virus flag, though older malware-port list aggregations vaguely and inconsistently cite the port, so no specific malware attribution is asserted here.

IANA assignment
ibm-app — "IBM Application"; reference (blank — no RFC cited in IANA registry); assignee Lisa Tomita; dual-registered 385/tcp + 385/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, line 764; corroborated at https://www.portdb.io/port_pages/port_385_-_512.html
Range class
well-known (0–1023) [Confirmed]
Prevalence
not separately reported in the checked nmap-services frequency data for 385/udp; SANS ISC actively tracks background scan visibility on port 385 [Likely] — https://isc.sans.edu/data/port/385
Related ports
385/tcp (same ibm-app registration) [Confirmed]

Primary use

unspecified legacy IBM application; no public protocol documentation found

[Unknown] — no RFC/reference on file

Other/unofficial uses

none identified in community sources (vendor docs, blogs, forums) [Unknown]

Security implications

no named legitimate software found; scanning traffic is routine and unattributed at normal threat level; malware attribution is unconfirmed/conflicting across sources

[Likely] — https://isc.sans.edu/data/port/385, https://www.auditmypc.com/udp-port-385.asp

Typically seen on

unknown — no environment or vendor deployment identified [Unknown]

Analyst note
treat an open 385/udp as anomalous given the absence of any confirmed legitimate use; corroborate with process/service identification on the host before assuming it is benign.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ibm-app UDP IBM Application 0.07%
ibm-app TCP IBM Application 0.00%
IANA name
ibm-app
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.