Network port detail · UDP/TCP

398

Kryptolan
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — Kryptolan is a dormant IANA registration with no documented protocol, vendor implementation, or meaningful scan prevalence, so a responsive host on 398/tcp is unexplained and should be investigated rather than assumed legitimate.
// analyst note
an open port 398 has no known legitimate explanation — treat it as unexplained and investigate rather than attribute it to Kryptolan by default.
// if you see it open
No legitimate, documented service is known to run on 398/tcp. A single 2014 third-party scan (nknetobserver corpus) found the port open on one host but nmap could not fingerprint any service behind it — an unverified single sighting, not confirmation of Kryptolan or any other software. No CVE or malware family is documented as associated with this port. A responsive host on 398 should be treated as anomalous and investigated.
[ 01 ] — Context

About port 398/tcp.

Updated  ·  Confidence: Medium

Port 398/tcp carries no identifiable active service; IANA lists it under the registered name "Kryptolan" with no accompanying protocol specification, and it should not be exposed to or expected on the public internet.

The IANA Service Name and Transport Protocol Port Number Registry assigns 398/tcp and 398/udp to "Kryptolan," a dual-registered name with assignee Peter de Laval and a blank Reference field — no RFC or other technical document is cited. No public protocol specification, vendor implementation, or open-source project matching "Kryptolan" could be located.

Prevalence data supports this: the nmap-services corpus records 398/tcp at an open-frequency of essentially 0.000000, meaning it is almost never seen open in real-world scans. A single 2014 third-party scan (nknetobserver corpus) found 398/tcp open on one host, but nmap could not fingerprint any service behind it — an unverified single sighting, not confirmation that Kryptolan or anything else runs there.

Given the absence of a spec, a shipping implementation, or meaningful scan prevalence, port 398 is best treated as a dormant legacy IANA registration. Any live traffic observed on it is unexplained rather than attributable to a known application and merits manual investigation rather than automatic labeling.

IANA assignment
kryptolan — "Kryptolan"; reference (blank — no RFC cited in the IANA registry); assignee Peter de Laval; dual-registered 398/tcp + 398/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed] — port numbering convention
Prevalence
nmap-services open-frequency for 398/tcp ≈ 0.000000 (essentially never observed open) [Confirmed] — nmap-services file
Related ports
none specifically associated with this registration [Unknown]

Primary use

registered name only, no documented protocol or specification exists for it

[Confirmed/Likely] — IANA registry blank Reference field

Other/unofficial uses

none identified in vendor docs, forums, or scan corpora

[Unknown] — no source located

Security implications

essentially never legitimately open; one unverified 2014 scan hit with no fingerprinted service; no documented CVE or malware association

[Likely] — nknetobserver scan corpus

Typically seen on

no known legitimate hosts; a response on 398 is an anomaly worth investigating

[Likely] — absence of any documented deployment
Analyst note
an open port 398 has no known legitimate explanation — treat it as unexplained and investigate rather than attribute it to Kryptolan by default.
[ 02 ] — Context

About port 398/udp.

Updated  ·  Confidence: Low

Port 398/udp is registered with IANA under the service name kryptolan, but no research angle surfaced any evidence of an application actively using it today, so an open 398/udp is best treated as unexpected rather than as a service that belongs facing the public internet.

The IANA registry lists the service name kryptolan, description "Kryptolan," assignee recorded as the bracketed contact [Peter_de_Laval], and a blank Reference column — no RFC or other formal specification is cited. The entry is dual-registered on both 398/tcp and 398/udp.

The name and registrant point to Kryptolan, associated with a "LAN/WAN Krypto" (LWK) secure transport/data-object protection protocol tied to Peter de Laval and Sectra, a Swedish security-technology company. This attribution is corroborated by the registry contact and third-party port-lookup references, but no independent technical specification or deployment documentation was found, so it stays a Likely-confidence inference rather than a confirmed fact.

Measured real-world open-port frequency for 398/udp is 0.000659 (nmap-services empirical scan-frequency dataset, recorded in the repo's canonical this site's own tooling artifact), consistent with a port that is registered but essentially never seen open in the wild.

No credible reports of current real-world traffic on this port were found. A community forum thread from a user unable to identify software generating traffic on port 398 ended without resolution. A port-lookup database (AuditMyPC) was checked directly for a malware association and returned a confirmed negative: its verdict line for UDP port 398 reads "Virus / Trojan: No," and the page's Trojan/Virus explanatory sentence is boilerplate text printed identically across the site regardless of a port's actual flag status — it is not evidence of any historical or current malware association with this port.

IANA assignment
kryptolan — "Kryptolan"; reference (blank — no RFC cited in IANA registry); assignee [Peter_de_Laval]; dual-registered 398/tcp + 398/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 790); IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023 range assigned by IANA; not in the 1024–49151 registered band despite the "registered" style of the assignment) [Confirmed] — IANA registry; this site's own tooling (range: "system")
Prevalence
0.000659 measured open-port frequency for 398/udp (nmap-services empirical scan dataset) [Confirmed] — this site's own tooling
Related ports
398/tcp (dual registration, same kryptolan service name, frequency 0 in port-data.json) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; this site's own tooling

Primary use

Kryptolan, reported as a "LAN/WAN Krypto" (LWK) secure transport/data-object protection protocol associated with registrant Peter de Laval and Sectra (Sweden) [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=398, https://www.speedguide.net/port.php?port=398

Other/unofficial uses

none credibly documented; a community thread found no application explanation for observed traffic

[Unknown] — https://macosx.com/threads/driving-me-insane-what-is-port-398.259225/

Security implications

no malware association found — AuditMyPC's port database returns a confirmed "Virus / Trojan: No" verdict for UDP 398; no confirmed legitimate deployment beyond the registrant's own Kryptolan/LWK protocol [Confirmed negative on malware / Likely on no legitimate deployment] — https://www.auditmypc.com/udp-port-398.asp

Typically seen on

no host type is documented in any reviewed source for this port

[Unknown] — no source surfaced a typical deployment context
Analyst note
An open port 398/udp lacks a confirmed legitimate use case; investigate as anomalous rather than assuming routine service traffic.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
kryptolan UDP 0.07%
kryptolan TCP 0.00%
IANA name
kryptolan
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.