Network port detail · UDP/TCP

412

Synoptics-trap
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No first-party evidence shows a currently-deployed, security-critical service on 412; if open it most likely reflects a legacy/unused IANA registration or unofficial legacy P2P (Direct Connect) client traffic, so it should be investigated rather than treated as expected.
// common applications
NeoModus Direct Connect (DC++) Traffic on this port is most often routine background internet scanning; community sources report that legacy NeoModus Direct Connect (DC++) P2P clients have used 412/tcp for client-to-client transfers, though this is an unofficial and hedged sighting, not an IANA-documented use.
// analyst note
Port 412 is officially registered but has no documented live service; treat an open instance as legacy, community-sourced P2P (DC++), or anomalous, and investigate the specific host.
// if you see it open
No confirmed active-malware family is associated with 412; auditmypc.com's own verdict line for 412/tcp reads "Virus / Trojan: No" (none documented). SANS ISC shows only low-volume background internet scan noise consistent with routine mass scanning, not a targeted campaign. Community sources (SANS ISC forum comment, 2003; whatportis.com) associate 412/tcp with legacy NeoModus Direct Connect (DC++) client-to-client P2P traffic, an unofficial and insecure protocol usage; no other application is credibly documented on this port.
[ 01 ] — Context

About port 412/tcp.

Updated  ·  Confidence: Medium

Port 412/tcp is registered with IANA as synoptics-trap, the "Trap Convention Port" — a legacy, SNMP-adjacent trap-notification registration with no currently-documented, actively-deployed service running under that name; it is not something that should normally be reachable, and an open 412 should be treated as internal-only or investigated as an anomaly rather than assumed to be a live business service.

The IANA registry confirms 412 is dual-registered on both TCP and UDP, assignee Illan Raab, with a blank Reference field — no RFC is cited for this entry, and none should be inferred. The generic "Trap Convention Port" description is distinct from the well-known SNMP trap port 162/udp.

No widely-deployed, currently-specified protocol is documented on 412 today. Community sources instead associate 412/tcp with legacy NeoModus Direct Connect (DC++) peer-to-peer file-sharing: a 2003 SANS Internet Storm Center forum comment and a secondary port-database aggregator (whatportis.com) both describe 412 as a client-to-client (C2C) transfer port once a hub connection (traditionally on 411/tcp) is established. This sighting is unofficial and hedged, not an IANA-documented use.

Security posture is likewise unconfirmed rather than alarming: no specific active malware family is tied to this port, and observed scan traffic reads as routine internet-wide background noise.

IANA assignment
synoptics-trap — "Trap Convention Port"; reference (blank — no RFC cited); assignee Illan Raab; dual-registered 412/tcp + 412/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 817-818
Range class
well-known (0–1023)
Prevalence
nmap-services open-frequency for 412/tcp ≈0.000025 [Confirmed] — nmap-services dataset (this site's own tooling)
Related ports
162/udp (SNMP trap, the well-known trap port this registration is distinct from); 411/tcp (traditional Direct Connect hub port, related to the community-sourced C2C use of 412) [Likely]

Primary use

generic SNMP-adjacent trap-notification convention (synoptics-trap); distinct from the well-known SNMP trap port 162; no actively-specified service documented as currently deployed on 412

[Likely] — IANA registry

Other/unofficial uses

community-sourced legacy NeoModus Direct Connect (DC++) client-to-client (C2C) P2P file-sharing traffic

[Likely] — SANS ISC (2003 comment), whatportis.com

Security implications

no confirmed active malware family; auditmypc.com's own verdict line for 412/tcp reads "Virus / Trojan: No" (none documented); SANS ISC shows only routine low-volume scan noise, not a targeted campaign

[Likely] — auditmypc.com, isc.sans.edu

Typically seen on

legacy/unused IANA registrations; possible legacy Direct Connect (DC++) P2P client-to-client traffic; otherwise scan noise or anomaly [Likely]

Analyst note
Port 412 is officially registered but has no documented live service; treat an open instance as legacy, community-sourced P2P (DC++), or anomalous, and investigate the specific host.
[ 02 ] — Context

About port 412/udp.

Updated  ·  Confidence: Medium

Port 412/udp carries synoptics-trap, a legacy SNMP-style trap-notification service tied to SynOptics/Bay Networks network management products; it should stay internal-only rather than exposed to the public internet.

IANA's Service Name and Transport Protocol Port Number Registry lists 412 as synoptics-trap with the description "Trap Convention Port," registered identically on both TCP and UDP under assignee [Illan_Raab]. No RFC reference is cited for this assignment, and the registry records no registration or modification date — both fields are left blank rather than invented.

Historically, this port was used by SynOptics Communications' network management software to receive unsolicited trap/alert messages from managed network devices, functioning in a role similar to the standard SNMP trap port 162/udp but under a vendor-specific service name. SynOptics merged into Bay Networks in 1994, and Bay Networks was acquired by Nortel in 1998; the related SynOptics Network Management Protocol (SONMP) evolved into the Nortel Discovery Protocol, used in later Nortel Optivity / Unified Communications Management products.

The nmap-services corpus records a scan-prevalence figure for this transport — an open-frequency of ≈0.000511 (this site's own tooling) — though no dated Shodan/Censys scan-prevalence figures, CVE, or confirmed present-day software attribution for 412/udp were found in this research pass. Generic port-database sites note that some historical Trojans have used arbitrary low-numbered ports for command-and-control, but this is a boilerplate disclaimer these sites attach broadly, not a documented finding specific to 412.

IANA assignment
synoptics-trap — "Trap Convention Port"; reference (blank — no RFC cited in IANA registry); assignee [Illan_Raab]; dual-registered 412/tcp + 412/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
nmap-services open-frequency for 412/udp ≈0.000511 [Confirmed] — nmap-services dataset (this site's own tooling)
Related ports
162/udp (standard SNMP trap port, analogous role) [Likely]

Primary use

legacy SNMP-style trap-notification port for SynOptics Communications network management software

[Likely] — Wikipedia (Bay Networks, Nortel Discovery Protocol)

Other/unofficial uses

no confirmed uses beyond vendor-lineage context (SynOptics → Bay Networks → Nortel Optivity/Unified Communications Management)

[Unknown] — tek-tips forum thread, Wikipedia

Security implications

no legitimate public-facing use; generic low-port Trojan disclaimer only on port-database sites, no specific CVE or malware family confirmed for 412/udp

[Unknown] — AuditMyPC, SpeedGuide, GRC

Typically seen on

legacy SynOptics/Bay Networks/Nortel network-management hosts

[Likely] — Wikipedia
Analyst note
treat a responsive 412/udp as a legacy management-plane indicator to investigate, not as an active or common attack surface.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
synoptics-trap UDP Trap Convention Port 0.05%
synoptics-trap TCP Trap Convention Port 0.00%
IANA name
synoptics-trap
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.