398
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — Kryptolan is a dormant IANA registration with no documented protocol, vendor implementation, or meaningful scan prevalence, so a responsive host on 398/tcp is unexplained and should be investigated rather than assumed legitimate.
- // analyst note
- an open port 398 has no known legitimate explanation — treat it as unexplained and investigate rather than attribute it to Kryptolan by default.
- // if you see it open
- No legitimate, documented service is known to run on 398/tcp. A single 2014 third-party scan (nknetobserver corpus) found the port open on one host but nmap could not fingerprint any service behind it — an unverified single sighting, not confirmation of Kryptolan or any other software. No CVE or malware family is documented as associated with this port. A responsive host on 398 should be treated as anomalous and investigated.
About port 398/tcp.
Port 398/tcp carries no identifiable active service; IANA lists it under the registered name "Kryptolan" with no accompanying protocol specification, and it should not be exposed to or expected on the public internet.
The IANA Service Name and Transport Protocol Port Number Registry assigns 398/tcp and 398/udp to "Kryptolan," a dual-registered name with assignee Peter de Laval and a blank Reference field — no RFC or other technical document is cited. No public protocol specification, vendor implementation, or open-source project matching "Kryptolan" could be located.
Prevalence data supports this: the nmap-services corpus records 398/tcp at an open-frequency of essentially 0.000000, meaning it is almost never seen open in real-world scans. A single 2014 third-party scan (nknetobserver corpus) found 398/tcp open on one host, but nmap could not fingerprint any service behind it — an unverified single sighting, not confirmation that Kryptolan or anything else runs there.
Given the absence of a spec, a shipping implementation, or meaningful scan prevalence, port 398 is best treated as a dormant legacy IANA registration. Any live traffic observed on it is unexplained rather than attributable to a known application and merits manual investigation rather than automatic labeling.
- IANA assignment
kryptolan— "Kryptolan"; reference (blank — no RFC cited in the IANA registry); assignee Peter de Laval; dual-registered 398/tcp + 398/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed] — port numbering convention
- Prevalence
- nmap-services open-frequency for 398/tcp ≈ 0.000000 (essentially never observed open) [Confirmed] — nmap-services file
- Related ports
- none specifically associated with this registration [Unknown]
Primary use
registered name only, no documented protocol or specification exists for it
Other/unofficial uses
none identified in vendor docs, forums, or scan corpora
Security implications
essentially never legitimately open; one unverified 2014 scan hit with no fingerprinted service; no documented CVE or malware association
Typically seen on
no known legitimate hosts; a response on 398 is an anomaly worth investigating
- Analyst note
- an open port 398 has no known legitimate explanation — treat it as unexplained and investigate rather than attribute it to Kryptolan by default.
About port 398/udp.
Port 398/udp is registered with IANA under the service name kryptolan, but no research angle surfaced any evidence of an application actively using it today, so an open 398/udp is best treated as unexpected rather than as a service that belongs facing the public internet.
The IANA registry lists the service name kryptolan, description "Kryptolan," assignee recorded as the bracketed contact [Peter_de_Laval], and a blank Reference column — no RFC or other formal specification is cited. The entry is dual-registered on both 398/tcp and 398/udp.
The name and registrant point to Kryptolan, associated with a "LAN/WAN Krypto" (LWK) secure transport/data-object protection protocol tied to Peter de Laval and Sectra, a Swedish security-technology company. This attribution is corroborated by the registry contact and third-party port-lookup references, but no independent technical specification or deployment documentation was found, so it stays a Likely-confidence inference rather than a confirmed fact.
Measured real-world open-port frequency for 398/udp is 0.000659 (nmap-services empirical scan-frequency dataset, recorded in the repo's canonical this site's own tooling artifact), consistent with a port that is registered but essentially never seen open in the wild.
No credible reports of current real-world traffic on this port were found. A community forum thread from a user unable to identify software generating traffic on port 398 ended without resolution. A port-lookup database (AuditMyPC) was checked directly for a malware association and returned a confirmed negative: its verdict line for UDP port 398 reads "Virus / Trojan: No," and the page's Trojan/Virus explanatory sentence is boilerplate text printed identically across the site regardless of a port's actual flag status — it is not evidence of any historical or current malware association with this port.
- IANA assignment
kryptolan— "Kryptolan"; reference (blank — no RFC cited in IANA registry); assignee[Peter_de_Laval]; dual-registered 398/tcp + 398/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 790); IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023 range assigned by IANA; not in the 1024–49151 registered band despite the "registered" style of the assignment) [Confirmed] — IANA registry; this site's own tooling (range: "system")
- Prevalence
- 0.000659 measured open-port frequency for 398/udp (nmap-services empirical scan dataset) [Confirmed] — this site's own tooling
- Related ports
- 398/tcp (dual registration, same
kryptolanservice name, frequency 0 in port-data.json) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; this site's own tooling
Primary use
Kryptolan, reported as a "LAN/WAN Krypto" (LWK) secure transport/data-object protection protocol associated with registrant Peter de Laval and Sectra (Sweden) [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=398, https://www.speedguide.net/port.php?port=398
Other/unofficial uses
none credibly documented; a community thread found no application explanation for observed traffic
Security implications
no malware association found — AuditMyPC's port database returns a confirmed "Virus / Trojan: No" verdict for UDP 398; no confirmed legitimate deployment beyond the registrant's own Kryptolan/LWK protocol [Confirmed negative on malware / Likely on no legitimate deployment] — https://www.auditmypc.com/udp-port-398.asp
Typically seen on
no host type is documented in any reviewed source for this port
- Analyst note
- An open port 398/udp lacks a confirmed legitimate use case; investigate as anomalous rather than assuming routine service traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| kryptolan | UDP | — | 0.07% |
| kryptolan | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.