44
Summary
- // if you see it open
- No expected legitimate listener — the registered MPM service is obsolete and unused. Documented historical association with the 'Arctic' trojan (Backdoor.Arctic / ArticSimovits), an early-2000s Windows 9x (95/98/ME) RAT/keylogger/password-stealer that used TCP port 44 for command-and-control. No current (2024-2026) scanning campaigns, exploits, or CVEs specific to port 44 were found. Any open port 44/tcp on a modern host is anomalous and should be investigated as a possible backdoor or decoy.
- // analyst note
- The registered service is obsolete and effectively unused; treat any open port 44/tcp as anomalous and investigate (possible Arctic-family backdoor or decoy) rather than assuming a legitimate service.
About port 44/tcp.
Port 44/tcp is registered with IANA as mpm-flags with the description "MPM FLAGS Protocol," dual-registered on TCP and UDP, with the Assignee, Contact, Registration Date, Modification Date, and Reference fields all blank in the registry — no RFC is cited. The name belongs to the Message Processing Module (MPM), an experimental early-ARPA internetwork mail-transfer architecture described in RFC 759 (J. Postel, August 1980). MPM occupies a small cluster of adjacent well-known ports — port 45 (mpm, "Message Processing Module [recv]") is the data/receive port, and port 44 carries the FLAGS signaling role. It is worth being precise about provenance: RFC 759 describes MPM-to-MPM message exchange and references the MPM data port, but it does not enumerate port 44 by number; the mpm-flags label is an IANA registry assignment associated with the MPM port cluster, not a literal RFC 759 citation. Third-party port databases (e.g. EventTracker) that attribute "RFC 759" to port 44 are inferring from the MPM lineage rather than quoting an explicit assignment. The MPM architecture was experimental, never widely deployed, and is obsolete; no known active software implements this service today. For an analyst the registered service is effectively irrelevant — the port has no expected legitimate listener on a modern host. What carries practical weight is that port 44/tcp has a documented historical association with the "Arctic" backdoor (Backdoor.Arctic / ArticSimovits), a Windows 9x-era remote-access/keylogger/password-stealing trojan that used TCP port 44 for command-and-control; that association is early-2000s and targets obsolete Windows (95/98/ME). No current (2024–2026) scanning campaigns, exploits, or CVEs specific to port 44 were found in available threat-intelligence sources. Because the port has no active legitimate role, any open port 44/tcp listener on a modern host is anomalous and worth investigating as a possible backdoor or decoy rather than a normal service.
- IANA assignment
mpm-flags— "MPM FLAGS Protocol"; reference (blank — no RFC cited in IANA registry); assignee blank; dual-registered 44/tcp + 44/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 97–98)- Range class
- well-known (0–1023)
- IANA RFC reference
- none listed in the registry for
mpm-flags; third-party databases citing "RFC 759" are inferring from the MPM lineage, not quoting an explicit IANA/RFC assignment [Confirmed] — IANA registry; RFC 759; kb.eventtracker.com - Related ports
- MPM cluster — 45/tcp (
mpm, "Message Processing Module [recv]"); adjacent legacy assignments 42 (name/nameserver), 43 (nicname/whois) - Registration date
- Unknown — IANA does not publish registration dates for port assignments and no authoritative third-party date is available; none has been fabricated [Unknown]
Primary use
FLAGS signaling channel of the Message Processing Module (MPM), an experimental ARPA internetwork mail-transfer architecture; companion to the MPM data port 45 [Likely] — RFC 759 (J. Postel, Aug 1980) describes MPM but does not enumerate port 44 by number; the label is an IANA registry assignment
Common software
Unknown — no known modern software binds to port 44/tcp for the registered purpose; the MPM architecture (RFC 759, 1980) was experimental and never reached widespread adoption
Security implications
documented historical association with the "Arctic" trojan (Backdoor.Arctic / ArticSimovits), a Windows 9x-era RAT/keylogger/password-stealer that used TCP port 44 for C2; early-2000s, targets obsolete Windows (95/98/ME). No current scanning campaigns, exploits, or CVEs specific to port 44 found in 2024–2026 sources
Typically seen on
no expected legitimate listener; an open port 44/tcp on a modern host is anomalous and possibly a backdoor or decoy
- Analyst note
- The registered service is obsolete and effectively unused; treat any open port 44/tcp as anomalous and investigate (possible Arctic-family backdoor or decoy) rather than assuming a legitimate service.
About port 44/udp.
Port 44/udp is registered with IANA as mpm-flags with the description "MPM FLAGS Protocol," and a completely blank optional-column set: no assignee, no contact, no registration or modification date, and no reference. Port 44/tcp carries the identical registration, making this a dual tcp+udp assignment. The service name points at the Message Processing Module (MPM) of the Internet Message Protocol described in RFC 759 (J. Postel, ISI, August 1980), an early ARPANET-era message-relay design. That RFC is the source of the "MPM" label, but it specifies port 45 (55 octal) as the MPM port — not 44. Port 44 was registered as a separate "MPM FLAGS" companion channel whose exact original function is not described in any surviving public specification, and RFC 759 itself is Historic with no active IETF endorsement. The IANA Reference field is blank, and that blank is the actual registry value rather than missing data: third-party port databases that cite "RFC 759" alongside port 44 are reproducing a database artifact, since the RFC defines port 45, not 44. For an analyst, the practical picture is that 44/udp has no known active legitimate use today. The Internet Message Protocol was never widely deployed, and no current software is known to bind 44/udp for its registered purpose. (A circulating claim attributing port 44 to the Apache "MPM" Multi-Processing Module is unsubstantiated and conflates two unrelated meanings of the acronym — Apache does not use port 44.) The only documented malicious association is the legacy late-1990s/early-2000s "Arctic" trojan (also listed as Backdoor.Arctic / ArcticSimovits), a Windows 95/98/ME remote-access and keylogging tool sharing source with the "GirlFriend" trojan, historically tied to port 44 on TCP rather than UDP specifically. Because the port falls in the System (well-known) range and has no active service, any responsive 44/udp listener on a modern host is anomalous and worth investigating as a misconfiguration or a legacy backdoor rather than a normal service.
- IANA assignment
mpm-flags— "MPM FLAGS Protocol"; reference (blank — no RFC cited in IANA registry); assignee blank; dual-registered 44/tcp + 44/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (registries/service-names-port-numbers.csv line 98:mpm-flags,44,udp,MPM FLAGS Protocol,,,,,,,,)- Range class
- well-known / System Ports (0–1023) [Confirmed] — IANA registry
- Registration date
- Unknown — no IANA registration date is published for this entry; third-party "date registered" values are database artifacts and are not sourced from IANA (and IEEE publishes no port dates) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
- IANA reference
- blank in the registry; "RFC 759" associations in third-party databases are artifacts (RFC 759 defines port 45) [Confirmed] — https://datatracker.ietf.org/doc/html/rfc759
- Related ports
- 44/tcp (identical mpm-flags registration); 45/udp (the actual MPM port per RFC 759)
Primary use
name references the Message Processing Module of the Internet Message Protocol (RFC 759, Postel, Aug 1980); RFC 759 specifies port 45, not 44, so the "MPM FLAGS" companion registration for 44 has no surviving specification. No known active modern use
Other/unofficial uses
Unknown — no substantiated legitimate modern software binds 44/udp; the Apache "MPM" (Multi-Processing Module) attribution circulating in some search summaries is unverified and unrelated to the ARPANET-era Message Processing Module
Malware associations
legacy "Arctic" trojan (Backdoor.Arctic.06 / ArcticSimovits), a late-1990s/early-2000s Windows 95/98/ME remote-access + keylogging tool sharing source with "GirlFriend," historically associated with port 44 (TCP, not UDP-specific). No active modern campaigns on 44/udp identified
Exposure / scanning
not among the high-volume ports tracked by Shodan/Censys; no specific internet-wide scan data for 44/udp found in available sources. An open 44/udp listener is anomalous; default-deny is appropriate
Security implications
low current risk — obsolete registered protocol with no active deployment; the only documented malicious use is an outdated-Windows-era trojan. An open 44/udp port on a modern system is unexpected and could indicate misconfiguration or a legacy backdoor
Typically seen on
no expected legitimate population; any responder is an anomaly / possible backdoor or decoy
- Analyst note
- 44/udp has no known legitimate modern use. Treat a responsive port as anomalous and investigate; do not rely on the third-party "RFC 759" reference for port 44 — RFC 759 specifies port 45.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| mpm-flags | UDP | MPM FLAGS Protocol | 0.07% |
| mpm-flags | TCP | MPM FLAGS Protocol | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.