Network port detail · UDP/TCP

404

Nced
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No IANA description, RFC, or credible vendor/community documentation defines an actual protocol or application for this port, and measured scan telemetry (nmap-services open-frequency 0.000025) confirms negligible real-world prevalence, so an open instance should be treated as anomalous and investigated rather than assumed benign or expected.
// analyst note
An open port 404 has no documented legitimate service behind it — investigate as an anomaly rather than assume either a known-safe or known-malicious use.
// if you see it open
No confirmed malware family, CVE, or dated security advisory names this port. Auditmypc.com's port-directory pages carry a templated 'flagged as a virus/Trojan' warning, but the identical boilerplate is reused across thousands of unrelated port numbers on that site, so it is treated as low-credibility rather than a specific, sourced incident; the same page also prints an explicit 'Virus / Trojan: No' verdict, a sourced confirmed negative. As an unassigned-in-practice port with negligible measured scan prevalence (0.000025), unexpected traffic would be atypical and worth investigating, but there is no evidence of a documented scanning or exploitation campaign targeting it.
[ 01 ] — Context

About port 404/tcp.

Updated  ·  Confidence: Low

Port 404/tcp carries no documented protocol or software; IANA registers the number under the bare service name nced (dual-registered on tcp and udp) but supplies no description text and no RFC or document reference, so there is no sourced basis to call it internet-facing, restricted, or internal-only — an open instance is best treated as an anomaly to investigate rather than a known, expected service. Measured scan telemetry shows real-world exposure is negligible: nmap-services records this exact port/transport at an open-frequency of 0.000025.

The IANA Service Name and Transport Protocol Port Number Registry lists 404/tcp+udp as registered to the name "nced," but the Description column only repeats that name and the Reference column is blank. No RFC, internet-draft, or vendor protocol specification describing what "nced" actually does could be located.

Third-party port-lookup directories (SpeedGuide, t1shopper, GRC Port Authority, adminsub.net, auditmypc.com) all mirror the same bare "nced" label without elaboration. None names a specific application, game client, or commercial product that binds to this port, and no credible community sighting (vendor doc, blog post, forum thread) surfaced despite active searching. Auditmypc.com's own page prints an explicit verdict, "Virus / Trojan: No," a sourced confirmed negative distinct from its separate templated warning boilerplate (see Security below).

The port number's main public association is coincidental: it echoes the HTTP 404 "Not Found" status code. Some low-quality SEO port-directory pages explicitly flag this as a source of confusion rather than an actual technical relationship, and it should not be read as evidence of any real service.

IANA assignment
nced — description repeats the service name only, no elaboration; reference (blank — no RFC cited); dual-registered 404/tcp + 404/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, lines 801-802)
Range class
well-known (0–1023) [Confirmed]
Prevalence
0.000025 (nmap-services open-frequency for 404/tcp) [Confirmed] — this site's own tooling
Related ports
none functionally related; occasionally confused with the HTTP 404 "Not Found" status code, which is not a network-layer relationship [Likely] — auditmypc.com port-directory boilerplate

Primary use

Unknown — no RFC, internet-draft, or vendor specification documents what protocol or software "nced" implements

[Unknown] — IANA registry (description/reference fields blank)

Other/unofficial uses

none documented; no game client, P2P client, or commercial product found using this port

[Unknown] — SpeedGuide, auditmypc.com, t1shopper, GRC Port Authority (all mirror the bare IANA name with no elaboration)

Security implications

no confirmed malware family, CVE, or dated advisory names this port; a templated "flagged as a virus" warning on auditmypc.com is reused across unrelated ports and is low-credibility, while the same page's explicit "Virus / Trojan: No" verdict is a sourced confirmed negative

[Confirmed/Likely] — https://www.auditmypc.com/tcp-port-404.asp, https://www.auditmypc.com/udp-port-404.asp

Typically seen on

Unknown — not observed as belonging to any documented host role; presence would be atypical [Unknown]

Analyst note
An open port 404 has no documented legitimate service behind it — investigate as an anomaly rather than assume either a known-safe or known-malicious use.
[ 02 ] — Context

About port 404/udp.

Updated  ·  Confidence: Low

Port 404/udp is registered with IANA under the bare service name nced, but the registry supplies no protocol description, no RFC reference, and no assignment date — so what actually runs on this port, and whether it should ever be reachable from the public internet, is Unknown rather than confirmed safe or confirmed risky.

IANA's Service Names and Port Numbers registry lists nced as the service name for both 404/tcp and 404/udp (dual-registered), with the Reference column left blank. No RFC or IETF draft cites this assignment. Cross-checking the nmap-services master file, which mirrors the same IANA data, shows it does carry one measured datum beyond the bare name: an open-frequency of 0.000478 for 404/udp, about 19x the paired 404/tcp figure of 0.000025 (this site's own tooling). No expansion of the acronym or explanation of its original purpose could be located in any citable, live source.

Several port-lookup aggregator sites (SpeedGuide, adminsub.net, auditmypc.com, among others) simply mirror the same IANA entry without adding independently verifiable detail. No vendor documentation, blog post, or forum/support thread was found describing real-world software that emits traffic on UDP port 404, and no trojan or malware port list associates this port with a known malicious tool.

No protocol specification, application, or reported incident is documented anywhere for nced. The registry facts are the only confirmed information about this port; its real-world usage and risk profile are undetermined.

IANA assignment
nced — no description provided; Reference column blank; dual-registered on 404/tcp and 404/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 802
Range class
well-known (0–1023) [Confirmed]
Prevalence
404/udp carries a measured open-frequency of 0.000478 in the nmap-services dataset, about 19x the paired 404/tcp figure of 0.000025 [Confirmed] — this site's own tooling
Related ports
404/tcp (same nced dual registration) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 801-802

Primary use

Unknown — no protocol specification, RFC, or vendor documentation found for nced

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv

Other/unofficial uses

none found in web/vendor/forum research; no malware/trojan port lists associate this port with a known tool [Unknown] — http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html, https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_ports_list.csv

Security implications

no documented exposure or CVE; recommend treating an unexpected open responder as anomalous [Likely]

Typically seen on

no hosts or vendors documented [Unknown]

Analyst note
A sourced Unknown — this port has no confirmed legitimate use; an active responder deserves investigation rather than being assumed safe.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
nced UDP 0.05%
nced TCP 0.00%
IANA name
nced
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.