404
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No IANA description, RFC, or credible vendor/community documentation defines an actual protocol or application for this port, and measured scan telemetry (nmap-services open-frequency 0.000025) confirms negligible real-world prevalence, so an open instance should be treated as anomalous and investigated rather than assumed benign or expected.
- // analyst note
- An open port 404 has no documented legitimate service behind it — investigate as an anomaly rather than assume either a known-safe or known-malicious use.
- // if you see it open
- No confirmed malware family, CVE, or dated security advisory names this port. Auditmypc.com's port-directory pages carry a templated 'flagged as a virus/Trojan' warning, but the identical boilerplate is reused across thousands of unrelated port numbers on that site, so it is treated as low-credibility rather than a specific, sourced incident; the same page also prints an explicit 'Virus / Trojan: No' verdict, a sourced confirmed negative. As an unassigned-in-practice port with negligible measured scan prevalence (0.000025), unexpected traffic would be atypical and worth investigating, but there is no evidence of a documented scanning or exploitation campaign targeting it.
About port 404/tcp.
Port 404/tcp carries no documented protocol or software; IANA registers the number under the bare service name nced (dual-registered on tcp and udp) but supplies no description text and no RFC or document reference, so there is no sourced basis to call it internet-facing, restricted, or internal-only — an open instance is best treated as an anomaly to investigate rather than a known, expected service. Measured scan telemetry shows real-world exposure is negligible: nmap-services records this exact port/transport at an open-frequency of 0.000025.
The IANA Service Name and Transport Protocol Port Number Registry lists 404/tcp+udp as registered to the name "nced," but the Description column only repeats that name and the Reference column is blank. No RFC, internet-draft, or vendor protocol specification describing what "nced" actually does could be located.
Third-party port-lookup directories (SpeedGuide, t1shopper, GRC Port Authority, adminsub.net, auditmypc.com) all mirror the same bare "nced" label without elaboration. None names a specific application, game client, or commercial product that binds to this port, and no credible community sighting (vendor doc, blog post, forum thread) surfaced despite active searching. Auditmypc.com's own page prints an explicit verdict, "Virus / Trojan: No," a sourced confirmed negative distinct from its separate templated warning boilerplate (see Security below).
The port number's main public association is coincidental: it echoes the HTTP 404 "Not Found" status code. Some low-quality SEO port-directory pages explicitly flag this as a source of confusion rather than an actual technical relationship, and it should not be read as evidence of any real service.
- IANA assignment
nced— description repeats the service name only, no elaboration; reference (blank — no RFC cited); dual-registered 404/tcp + 404/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, lines 801-802)- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- 0.000025 (nmap-services open-frequency for 404/tcp) [Confirmed] —
this site's own tooling - Related ports
- none functionally related; occasionally confused with the HTTP 404 "Not Found" status code, which is not a network-layer relationship [Likely] — auditmypc.com port-directory boilerplate
Primary use
Unknown — no RFC, internet-draft, or vendor specification documents what protocol or software "nced" implements
Other/unofficial uses
none documented; no game client, P2P client, or commercial product found using this port
Security implications
no confirmed malware family, CVE, or dated advisory names this port; a templated "flagged as a virus" warning on auditmypc.com is reused across unrelated ports and is low-credibility, while the same page's explicit "Virus / Trojan: No" verdict is a sourced confirmed negative
Typically seen on
Unknown — not observed as belonging to any documented host role; presence would be atypical [Unknown]
- Analyst note
- An open port 404 has no documented legitimate service behind it — investigate as an anomaly rather than assume either a known-safe or known-malicious use.
About port 404/udp.
Port 404/udp is registered with IANA under the bare service name nced, but the registry supplies no protocol description, no RFC reference, and no assignment date — so what actually runs on this port, and whether it should ever be reachable from the public internet, is Unknown rather than confirmed safe or confirmed risky.
IANA's Service Names and Port Numbers registry lists nced as the service name for both 404/tcp and 404/udp (dual-registered), with the Reference column left blank. No RFC or IETF draft cites this assignment. Cross-checking the nmap-services master file, which mirrors the same IANA data, shows it does carry one measured datum beyond the bare name: an open-frequency of 0.000478 for 404/udp, about 19x the paired 404/tcp figure of 0.000025 (this site's own tooling). No expansion of the acronym or explanation of its original purpose could be located in any citable, live source.
Several port-lookup aggregator sites (SpeedGuide, adminsub.net, auditmypc.com, among others) simply mirror the same IANA entry without adding independently verifiable detail. No vendor documentation, blog post, or forum/support thread was found describing real-world software that emits traffic on UDP port 404, and no trojan or malware port list associates this port with a known malicious tool.
No protocol specification, application, or reported incident is documented anywhere for nced. The registry facts are the only confirmed information about this port; its real-world usage and risk profile are undetermined.
- IANA assignment
nced— no description provided; Reference column blank; dual-registered on 404/tcp and 404/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 802- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- 404/udp carries a measured open-frequency of 0.000478 in the nmap-services dataset, about 19x the paired 404/tcp figure of 0.000025 [Confirmed] — this site's own tooling
- Related ports
- 404/tcp (same
nceddual registration) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 801-802
Primary use
Unknown — no protocol specification, RFC, or vendor documentation found for nced
Other/unofficial uses
none found in web/vendor/forum research; no malware/trojan port lists associate this port with a known tool [Unknown] — http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html, https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_ports_list.csv
Security implications
no documented exposure or CVE; recommend treating an unexpected open responder as anomalous [Likely]
Typically seen on
no hosts or vendors documented [Unknown]
- Analyst note
- A sourced Unknown — this port has no confirmed legitimate use; an active responder deserves investigation rather than being assumed safe.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| nced | UDP | — | 0.05% |
| nced | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.