405
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — This is a legacy IANA registration with no confirmed legitimate application using it today and a measured zero open-scan frequency, so a responsive port 405 should be treated as anomalous and investigated rather than assumed to be routine traffic.
- // analyst note
- An open port 405 has no known legitimate modern use and measures a zero open-scan frequency in the canonical dataset; investigate rather than assume routine service traffic.
- // if you see it open
- No substantiated exposure or scanning data was found for 405/tcp beyond a confirmed-zero measured open-scan frequency (functions/_lib/port-data.json). auditmypc.com's port-405 page records verdict 'Virus / Trojan: No' — NOT associated with malware; the only trojan-adjacent text on that page is generic site-wide template boilerplate reused across all of the site's port pages, not a port-405-specific finding. Port 405 is sometimes confused with IMSP (Interactive Mail Support Protocol); the IMSP specification itself assigns that protocol to TCP port 406, not 405.
About port 405/tcp.
Port 405/tcp carries no confirmed application today; it is a legacy IANA registration under the name ncld with no surviving specification, so a responsive host on this port should generally stay off the public internet and be treated as anomalous rather than routine service traffic.
The IANA Service Name and Transport Protocol Port Number Registry lists 405/tcp (and 405/udp) identically as ncld, with assignee and contact recorded as Richard Jones, no RFC or reference cited, and no expanded description beyond the repeated name. This is a legacy-era registration that predates the modern registration-template requirement, so a bare, uncited entry is expected rather than a data gap.
What ncld stands for could not be verified from any primary source. Low-quality, unsourced port-list sites offer guesses such as "Network Common Log Daemon," but none are corroborated by IANA or any other authoritative reference, so no expansion is stated as fact here.
Port 405 is sometimes confused with IMSP (Interactive Mail Support Protocol); the IMSP specification itself assigns that protocol to TCP port 406, not 405.
Scan-prevalence data confirms this dormancy directly: the in-repo nmap-services-derived dataset records a measured open-scan frequency of 0 for 405/tcp specifically — a real zero, not a missing figure — consistent with a port that sees essentially no legitimate traffic on the open internet.
- IANA assignment
ncld— description "ncld" (no expansion given); reference (blank — no RFC cited); assignee/contact Richard Jones; dual-registered 405/tcp + 405/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- 405/tcp measured open-scan frequency = 0.000000 (a real measured zero, not an absence of data); 405/udp carries a distinct non-zero figure (0.000379) in the same artifact and is not conflated here [Confirmed] — this site's own tooling
- Related ports
- 406/tcp (IMSP — commonly confused with 405 but is a distinct, unrelated port)
Primary use
no documented, verifiable primary use survives; no known reference implementation or corroborated real-world protocol traffic
Other/unofficial uses
none verified [Unknown]
Security implications
no substantiated exposure or scanning data found beyond a confirmed-zero scan frequency; port appears effectively dormant/legacy; auditmypc.com's own verdict for 405 is "Virus / Trojan: No"; port 405 is sometimes confused with IMSP (Interactive Mail Support Protocol), but the IMSP specification itself assigns that protocol to TCP port 406, not 405
Typically seen on
no confirmed legitimate hosts identified; treat a responsive instance as an anomaly, decoy, or possible backdoor candidate [Unknown]
- Analyst note
- An open port 405 has no known legitimate modern use and measures a zero open-scan frequency in the canonical dataset; investigate rather than assume routine service traffic.
About port 405/udp.
Port 405/udp carries no defined, actively used protocol; IANA's registration for this port is a bare legacy service name with no expanded description and no cited specification, so nothing here should be treated as a recognized public-facing service, and a live listener deserves scrutiny rather than being assumed benign.
IANA lists 405 as dual-registered on both TCP and UDP under the same service name "ncld," assignee Richard Jones, with the Reference column blank — no RFC or specification was ever cited for this assignment. No registration or modification date is recorded in the source registry, which is consistent with other older, sparsely-documented entries.
Web research surfaced no vendor documentation, blog post, forum thread, or game/P2P client naming a specific piece of software that generates traffic on 405/udp today. General port-lookup aggregator sites (SpeedGuide, AuditMyPC, adminsub.net) simply mirror the same bare IANA listing without attributing a named application, so nothing should be inferred from the label "ncld" alone.
The nmap-services open-frequency figure for 405/udp is 0.000379 — low, but not zero. The paired 405/tcp side measures 0 in the same dataset, so any real-world sighting activity on this dual-registered pair is concentrated on the UDP side.
AuditMyPC's port-405 page carries a "Virus / Trojan: No" verdict — it does not flag the port as malware-associated. The page's boilerplate disclaimer text about historic virus/trojan flagging (site-wide template language explaining the color-coding scheme) prints regardless of a port's actual verdict and should not be read as a finding specific to 405; no CVE or dedicated trojan-port reference ties a malware family to this port.
Because the port has no documented legitimate use, any observed traffic is more likely reconnaissance, a misconfigured legacy service, or an anomaly than a recognized application.
- IANA assignment
ncld— no expanded description; reference blank; assignee Richard Jones; dual-registered 405/tcp + 405/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- 0.000379 (nmap-services open-frequency) [Confirmed] — this site's own tooling (paired 405/tcp measures 0 in the same dataset, so this port's sighting activity is concentrated on the UDP side)
- Related ports
- 405/tcp (same dual IANA registration under "ncld") [Confirmed] — IANA registry
Primary use
Unknown/legacy — no RFC or discoverable protocol specification defines an actual use for "ncld"
Other/unofficial uses
No vendor documentation, blog post, forum thread, or game/P2P client was found naming a specific application using 405/udp; only bare aggregator mirrors of the IANA listing exist
Security implications
no CVE or named malware family confirmed for 405/udp; AuditMyPC's port-405 page records "Virus / Trojan: No"
Typically seen on
no attributable software or host pattern documented; treat any live listener as anomalous [Unknown]
- Analyst note
- given the blank reference and absent protocol definition, an open 405/udp deserves investigation as a possible anomaly, misconfiguration, or unusual legacy service rather than assumption of a known application.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ncld | UDP | — | 0.04% |
| ncld | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.