415
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No confirmed real-world service or software uses port 415/tcp, so a listener here has no legitimate reason to exist and should be treated as unexpected rather than as a service designed for any network reach.
- // analyst note
- The "BNet" name invites confusion with Battle.net, but the two are unrelated; treat any traffic on 415/tcp as unexplained rather than assuming a gaming service.
- // if you see it open
- No CVEs or malware families are documented as targeting port 415/tcp. SANS Internet Storm Center's port-415 activity page shows only low-volume scanning (roughly two dozen distinct source IPs, single-digit hit counts each) with an overall 'green' (low-concern) status, consistent with routine internet background noise rather than a known exploit campaign. No confirmed real-world service runs on this port, so an open listener is anomalous and worth investigating.
About port 415/tcp.
Port 415/tcp is registered with IANA under the service name bnet ("BNet"), but no confirmed real-world software or service is documented as using it, so an open 415/tcp should be treated as anomalous rather than expected — there is no legitimate reason for it to be exposed to the public internet.
The IANA Service Name and Transport Protocol Port Number Registry lists 415 as a dual TCP/UDP assignment, description "BNet," assignee Jim Mertz. The Reference column is blank — no RFC documents the protocol — and the registration/modification dates are not recorded in the registry. This is an old-era assignment; the historic contact address (an @unisys.com domain) is consistent with the RFC 1700 (1994) "Assigned Numbers" era, though RFC 1700 is not IANA's cited reference for this entry today.
Despite the name, this port is unrelated to Blizzard's Battle.net gaming service, which historically used a different range (around 6112–6119 and 1119), not 415. No vendor documentation, blog posts, or forum threads were found attributing any specific application to port 415/tcp; port-reference aggregator sites simply mirror the bare IANA registration without adding sourced software attributions.
SANS Internet Storm Center's port-415 activity page shows only low-volume scanning — roughly two dozen distinct source IPs with single-digit hit counts each — and an overall "green" (low-concern) status, consistent with routine internet background noise rather than a known exploit campaign or malware family targeting this port.
- IANA assignment
bnet— "BNet"; reference blank (no RFC cited); assignee Jim Mertz; dual-registered 415/tcp + 415/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency for 415/tcp ≈0.000025 [Confirmed] — nmap-services dataset (this site's own tooling)
- Related ports
- none specifically documented as related; distinct from Blizzard Battle.net's historic 6112–6119 / 1119 range [Likely]
Primary use
formally reserved for a service called "BNet"; no documented functional specification or confirmed deployed use was found
Other/unofficial uses
none documented; historic contact address suggests an RFC-1700-era (1994) Unisys assignment, though RFC 1700 is not IANA's cited reference
Security implications
no known CVEs or malware target this port; SANS ISC shows only low-level routine background scanning with a "green" status
Typically seen on
no confirmed hosts/software; an open 415/tcp is an anomaly worth investigating [Likely]
- Analyst note
- The "BNet" name invites confusion with Battle.net, but the two are unrelated; treat any traffic on 415/tcp as unexplained rather than assuming a gaming service.
About port 415/udp.
Port 415/udp is IANA-registered under the service name bnet ("BNet"), but no confirmed, actively-used application has been identified running on it; the assignment reads as a dormant legacy registration rather than a live public-facing service, so a responsive 415/udp should be treated as anomalous and investigated rather than assumed benign.
The IANA registry lists 415 as dual-registered on both TCP and UDP, assignee Jim Mertz, with a blank Reference/RFC field and no registration date recorded. No protocol specification exists for this service in the registry — it is a name-and-contact entry only, with nothing describing what the service actually does on the wire.
A recurring misconception on lower-quality port-lookup aggregator sites labels port 415 as Blizzard Entertainment's "Battle.net." That is not IANA-supported: Battle.net conventionally uses TCP/UDP 6112–6119, and the IANA bnet name for port 415 is an unrelated legacy assignment tied to a named contact rather than a game platform.
SANS Internet Storm Center's port-415 activity page (checked 2026-08-01) showed only low-level background internet scanning — a handful of source IPs, each with a few connection attempts — with an overall "green" (low) threat indicator. That is consistent with routine broad-range reconnaissance rather than a known active exploit campaign, and it is a point-in-time snapshot rather than a stable historical statistic.
- IANA assignment
bnet— "BNet"; reference (blank — no RFC/document cited); assignee Jim Mertz; dual-registered 415/tcp + 415/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency for 415/udp ≈0.000445 [Confirmed] — nmap-services dataset (this site's own tooling)
- Related ports
- 413/414/416/417 (adjacent registered ports, no direct relation); 6112–6119/tcp+udp (Blizzard Battle.net — commonly confused with this port's name but unrelated)
Primary use
registered name only; no confirmed application or protocol specification tied to this port
Other/unofficial uses
none confirmed; frequently but incorrectly associated with Blizzard's Battle.net by aggregator sites
Security implications
essentially never legitimately open; dormant legacy IANA registration; SANS ISC shows only low-level background scanning as of 2026-08-01 (point-in-time); unsourced generic malware claims not treated as credible
Typically seen on
no known legitimate hosts; dormant registration, otherwise anomaly / possible scan target
- Analyst note
- A responsive 415/udp has no confirmed legitimate use case; treat it as anomalous, do not assume it is Battle.net traffic, and corroborate any malware claim independently before acting on it.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| bnet | UDP | — | 0.04% |
| bnet | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.