438
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No protocol, software, or documented legitimate deployment is tied to 438/tcp; the IANA entry is a bare, unexpanded name with no RFC, so an active listener has no known explanation and should be treated as anomalous rather than assumed safe.
- // analyst note
- An open 438/tcp has no known protocol, software, or documented legitimate use behind it — treat it as anomalous and investigate rather than assume routine traffic.
- // if you see it open
- No CVE or named malware family is recorded against 438/tcp in SANS Internet Storm Center or auditmypc.com as of an August 2026 search. SANS ISC's port-438 page carried no populated scanning statistics, top-scanning-IP data, or CVE links as of the same check. auditmypc.com's generic port-scan template returns a 'Virus/Trojan: No' verdict, usable only as a negative finding, not confirmation of legitimate use. No RFC or specification is registered for this port, unusual for a long-standing well-known-range assignment and consistent with a protocol that was never publicly documented.
About port 438/tcp.
Port 438/tcp is registered with IANA under the bare name dsfgw, but no protocol specification, software, or documented deployment is tied to it, so there is no known service here to judge safe for public-internet exposure — an unexpected listener on 438/tcp should be treated as unidentified and investigated rather than assumed benign.
IANA's Service Names and Port Numbers registry dual-registers 438 on both TCP and UDP under the identical name dsfgw, with assignee and contact both recorded as Andy McKeen. The Description field duplicates the service name rather than expanding it, and the Registration Date, Modification Date, and Reference columns are all blank — no RFC or specification is cited for this assignment.
No independent source clarifies what dsfgw denotes or runs. Searches across vendor documentation, technical forums, and port-reference sites turned up no product or protocol attribution — only mirrored copies of the same bare IANA listing on sites such as SpeedGuide and adminsub.net, as of an August 2026 search.
Threat-intelligence and scanning sources are similarly quiet. SANS Internet Storm Center's port-438 page carried no populated scanning statistics, top-scanning-IP data, or CVE links as of an August 2026 check. auditmypc.com's generic scan-report page returns a "Virus/Trojan: No" verdict for the port — a boilerplate template usable only as a negative data point, not confirmation of any association either way. No CVE was found tied to port 438 in either source as of the same search.
- IANA assignment
dsfgw— bare service name, Description field duplicates the name (no expansion); assignee and contact both Andy McKeen; dual-registered 438/tcp + 438/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (dsfgw 438/tcp, dsfgw 438/udp)- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 438/tcp ≈ 0.000013 (~0.001%, negligible); 438/udp ≈ 0.000725 (~0.07%) [Confirmed] — this site's own tooling
- Related ports
- 438/udp (dual-registered under the identical name dsfgw, same assignee) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (dsfgw 438/udp)
Primary use
Unknown — no RFC or protocol specification is referenced by IANA, and no independent source expands what dsfgw denotes, as of an August 2026 search
Other/unofficial uses
none found; searches of vendor documentation, forums, and port-reference sites surfaced only mirrored copies of the bare IANA listing (e.g. SpeedGuide, adminsub.net), as of an August 2026 search [Unknown]
Security implications
no CVE or named malware family recorded against 438/tcp in SANS ISC or auditmypc.com as of an August 2026 search; SANS ISC's port-438 page carried no populated scanning statistics or top-scanning-IP data as of the same check
Typically seen on
Unknown — no confirmed deployment context or software was identified in this research [Unknown]
- Analyst note
- An open 438/tcp has no known protocol, software, or documented legitimate use behind it — treat it as anomalous and investigate rather than assume routine traffic.
About port 438/udp.
Port 438/udp carries no documented protocol: IANA reserves the name dsfgw for it, but no RFC, vendor specification, or public writeup describes what traffic on this port actually does, so it has no established legitimate use that would justify exposing it to the public internet.
IANA's Service Name and Transport Protocol Port Number Registry lists dsfgw as a dual registration covering both 438/tcp and 438/udp, with contact Andy McKeen and a blank Reference column — no RFC is cited for either transport. The registry gives no expanded description beyond the bare service name itself, and no accompanying specification document is referenced anywhere in the entry.
Third-party port-list mirrors such as SpeedGuide, AdminSub, and t1shopper reproduce the identical unexpanded string with no added detail. As of an August 2026 search, no vendor documentation, RFC, or technical writeup anywhere describes an actual dsfgw protocol, and no forum, blog, or product manual reports software observed generating traffic on this port.
Measured real-world prevalence is very low: the nmap-services open-frequency data bundled with this site records 438/udp at approximately 0.000725 (about 0.07% of scanned hosts) and 438/tcp at approximately 0.000013 (about 0.001%) — consistent with a port that is registered but essentially unused.
With no documented protocol and near-zero observed usage, port 438/udp has nothing a defender should expect to see running. Any responsive host on this port merits direct investigation rather than being assumed to be a known, benign service.
- IANA assignment
dsfgw— no expanded description text; reference (blank — no RFC cited); assignee Andy McKeen; dual-registered 438/tcp + 438/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry; the IANA Service Name and Transport Protocol Port Number Registry dsfgw 438/udp- Range class
- well-known (0–1023) [Confirmed] — port number 438 falls in the IANA well-known range
- Prevalence
- nmap-services open-frequency 438/udp ≈ 0.000725 (~0.07%); 438/tcp ≈ 0.000013 (~0.001%) [Confirmed] — this site's own tooling (built from nmap-services)
- Related ports
- 438/tcp (dual-registered sibling; same undocumented status) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry dsfgw 438/tcp
Primary use
undocumented — no RFC, vendor specification, or technical writeup describes an actual protocol
Other/unofficial uses
none found in an August 2026 search [Unknown]
Security implications
no CVE recorded in the NVD as of 2026-08; no malware/trojan association confirmed as of an August 2026 search (auditmypc.com's port-438 page could not be retrieved); no documented legitimate use and near-zero prevalence
Typically seen on
no documented legitimate deployments found; treat a responsive host as anomalous [Unknown]
- Analyst note
- Port 438/udp has no documented protocol and near-zero observed prevalence — treat any responsive host as anomalous and investigate rather than assume a known service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dsfgw | UDP | — | 0.07% |
| dsfgw | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.