Network port detail · UDP/TCP

405

Ncld
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — This is a legacy IANA registration with no confirmed legitimate application using it today and a measured zero open-scan frequency, so a responsive port 405 should be treated as anomalous and investigated rather than assumed to be routine traffic.
// analyst note
An open port 405 has no known legitimate modern use and measures a zero open-scan frequency in the canonical dataset; investigate rather than assume routine service traffic.
// if you see it open
No substantiated exposure or scanning data was found for 405/tcp beyond a confirmed-zero measured open-scan frequency (functions/_lib/port-data.json). auditmypc.com's port-405 page records verdict 'Virus / Trojan: No' — NOT associated with malware; the only trojan-adjacent text on that page is generic site-wide template boilerplate reused across all of the site's port pages, not a port-405-specific finding. Port 405 is sometimes confused with IMSP (Interactive Mail Support Protocol); the IMSP specification itself assigns that protocol to TCP port 406, not 405.
[ 01 ] — Context

About port 405/tcp.

Updated  ·  Confidence: Low

Port 405/tcp carries no confirmed application today; it is a legacy IANA registration under the name ncld with no surviving specification, so a responsive host on this port should generally stay off the public internet and be treated as anomalous rather than routine service traffic.

The IANA Service Name and Transport Protocol Port Number Registry lists 405/tcp (and 405/udp) identically as ncld, with assignee and contact recorded as Richard Jones, no RFC or reference cited, and no expanded description beyond the repeated name. This is a legacy-era registration that predates the modern registration-template requirement, so a bare, uncited entry is expected rather than a data gap.

What ncld stands for could not be verified from any primary source. Low-quality, unsourced port-list sites offer guesses such as "Network Common Log Daemon," but none are corroborated by IANA or any other authoritative reference, so no expansion is stated as fact here.

Port 405 is sometimes confused with IMSP (Interactive Mail Support Protocol); the IMSP specification itself assigns that protocol to TCP port 406, not 405.

Scan-prevalence data confirms this dormancy directly: the in-repo nmap-services-derived dataset records a measured open-scan frequency of 0 for 405/tcp specifically — a real zero, not a missing figure — consistent with a port that sees essentially no legitimate traffic on the open internet.

IANA assignment
ncld — description "ncld" (no expansion given); reference (blank — no RFC cited); assignee/contact Richard Jones; dual-registered 405/tcp + 405/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
405/tcp measured open-scan frequency = 0.000000 (a real measured zero, not an absence of data); 405/udp carries a distinct non-zero figure (0.000379) in the same artifact and is not conflated here [Confirmed] — this site's own tooling
Related ports
406/tcp (IMSP — commonly confused with 405 but is a distinct, unrelated port)

Primary use

no documented, verifiable primary use survives; no known reference implementation or corroborated real-world protocol traffic

[Unknown] — IANA registry

Other/unofficial uses

none verified [Unknown]

Security implications

no substantiated exposure or scanning data found beyond a confirmed-zero scan frequency; port appears effectively dormant/legacy; auditmypc.com's own verdict for 405 is "Virus / Trojan: No"; port 405 is sometimes confused with IMSP (Interactive Mail Support Protocol), but the IMSP specification itself assigns that protocol to TCP port 406, not 405

[Confirmed] — this site's own tooling, auditmypc.com, IMSP specification

Typically seen on

no confirmed legitimate hosts identified; treat a responsive instance as an anomaly, decoy, or possible backdoor candidate [Unknown]

Analyst note
An open port 405 has no known legitimate modern use and measures a zero open-scan frequency in the canonical dataset; investigate rather than assume routine service traffic.
[ 02 ] — Context

About port 405/udp.

Updated  ·  Confidence: Low

Port 405/udp carries no defined, actively used protocol; IANA's registration for this port is a bare legacy service name with no expanded description and no cited specification, so nothing here should be treated as a recognized public-facing service, and a live listener deserves scrutiny rather than being assumed benign.

IANA lists 405 as dual-registered on both TCP and UDP under the same service name "ncld," assignee Richard Jones, with the Reference column blank — no RFC or specification was ever cited for this assignment. No registration or modification date is recorded in the source registry, which is consistent with other older, sparsely-documented entries.

Web research surfaced no vendor documentation, blog post, forum thread, or game/P2P client naming a specific piece of software that generates traffic on 405/udp today. General port-lookup aggregator sites (SpeedGuide, AuditMyPC, adminsub.net) simply mirror the same bare IANA listing without attributing a named application, so nothing should be inferred from the label "ncld" alone.

The nmap-services open-frequency figure for 405/udp is 0.000379 — low, but not zero. The paired 405/tcp side measures 0 in the same dataset, so any real-world sighting activity on this dual-registered pair is concentrated on the UDP side.

AuditMyPC's port-405 page carries a "Virus / Trojan: No" verdict — it does not flag the port as malware-associated. The page's boilerplate disclaimer text about historic virus/trojan flagging (site-wide template language explaining the color-coding scheme) prints regardless of a port's actual verdict and should not be read as a finding specific to 405; no CVE or dedicated trojan-port reference ties a malware family to this port.

Because the port has no documented legitimate use, any observed traffic is more likely reconnaissance, a misconfigured legacy service, or an anomaly than a recognized application.

IANA assignment
ncld — no expanded description; reference blank; assignee Richard Jones; dual-registered 405/tcp + 405/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
Range class
well-known (0–1023) [Confirmed]
Prevalence
0.000379 (nmap-services open-frequency) [Confirmed] — this site's own tooling (paired 405/tcp measures 0 in the same dataset, so this port's sighting activity is concentrated on the UDP side)
Related ports
405/tcp (same dual IANA registration under "ncld") [Confirmed] — IANA registry

Primary use

Unknown/legacy — no RFC or discoverable protocol specification defines an actual use for "ncld"

[Likely] — IANA registry

Other/unofficial uses

No vendor documentation, blog post, forum thread, or game/P2P client was found naming a specific application using 405/udp; only bare aggregator mirrors of the IANA listing exist

[Unknown] — SpeedGuide, AuditMyPC, adminsub.net aggregator listings

Security implications

no CVE or named malware family confirmed for 405/udp; AuditMyPC's port-405 page records "Virus / Trojan: No"

[Confirmed] — https://www.auditmypc.com/udp-port-405.asp

Typically seen on

no attributable software or host pattern documented; treat any live listener as anomalous [Unknown]

Analyst note
given the blank reference and absent protocol definition, an open 405/udp deserves investigation as a possible anomaly, misconfiguration, or unusual legacy service rather than assumption of a known application.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ncld UDP 0.04%
ncld TCP 0.00%
IANA name
ncld
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.