Network port detail · UDP/TCP

442

Cvc-hostd
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No protocol specification or legitimate current software is documented for cvc-hostd, and the one concrete security signal tied to 442/tcp is a malware command-and-control detection signature (Ramnit), so an open port 442/tcp does not correspond to an expected legitimate service and should be treated as anomalous if observed.
// analyst note
An open port 442 is statistically rare (nmap-services ~0.014% tcp) and has no documented legitimate current use; the one concrete security signal found is a Ramnit command-and-control detection signature, so treat a responsive 442/tcp as anomalous and worth investigating — do not assume a Cisco or VM host/guest function without further evidence.
// if you see it open
No CVE or NVD record is associated with 442/tcp as of an August 2026 search. auditmypc.com's TCP-442 page carries an explicit positive malware-indicator statement citing the Emerging Threats signature 'ET MALWARE Win32/Ramnit Checkin' (command-and-control category, described as low activity). SANS Internet Storm Center records ongoing low-volume scanning against port 442 as of an August 2026 check (threat level green; top single-source day one IP at 173 attempts). No legitimate software is documented using this port, so an open 442/tcp is anomalous and the malware signature makes a live listener worth treating with particular suspicion if observed.
[ 01 ] — Context

About port 442/tcp.

Updated  ·  Confidence: Low

Port 442/tcp is IANA-registered for a service named cvc-hostd, but IANA publishes no protocol specification beyond the bare name and no credible source documents legitimate software actively using it today, so an open 442/tcp does not belong on the public internet and any live listener deserves scrutiny rather than routine trust.

IANA's registry lists cvc-hostd on both TCP and UDP with assignee [Bill_Davidson] and a blank reference field — no RFC or specification document is cited, and no registration or modification date is recorded. A deprecated underscored alias, cvc_hostd, remains in the registry but is flagged historic and not usable with modern service-discovery mechanisms, since it fails RFC 6335's well-formedness rules.

No primary source explains what cvc-hostd actually does — IANA's own description merely notes that it replaced the older alias. Secondary port-lookup sites speculate about a Cisco secure-channel or VM host/guest communication function, but none cite supporting documentation, so that description should be read as unattributed folklore rather than a documented protocol.

Community consensus across several secondary ports-database mirrors, including SpeedGuide, is that 442/tcp is formally registered but practically unused; no vendor documentation, blog post, or forum thread names specific software binding to it as of an August 2026 search. The only concrete named association found is the malware family Ramnit, via a command-and-control detection signature rather than a legitimate-application sighting.

nmap-services open-frequency data puts 442/tcp at roughly 0.014% (442/udp at roughly 0.077%), consistent with a rarely-open port. SANS Internet Storm Center still records low-volume scanning against it as of an August 2026 check, and auditmypc.com flags an Emerging Threats signature for Ramnit command-and-control traffic on this port — reinforcing that a live listener is worth investigating rather than assumed legitimate.

IANA assignment
cvc-hostd — description notes only that it is "a well-formed service name as a replacement for 'cvc_hostd'"; Reference column blank (no RFC cited); Assignee/Contact [Bill_Davidson]; dual-registered 442/tcp + 442/udp; a deprecated underscored alias cvc_hostd also exists, flagged historic and not usable with modern service-discovery mechanisms
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry cvc-hostd 442/tcp, cvc_hostd 442/tcp
Range class
well-known (0–1023); source artifact labels this the "system" range [Confirmed] — this site's own tooling (port 442 entry)
Prevalence
nmap-services open-frequency 442/tcp ≈ 0.000138 (~0.014%); 442/udp ≈ 0.000774 (~0.077%) [Confirmed] — this site's own tooling (port 442 entry)
Related ports
442/udp (dual registration, same cvc-hostd service name and same historic cvc_hostd alias); sits among a run of individually-registered, unrelated legacy-era service names (440 sgcp, 441 decvms-sysmgt, 443 https) with no functional relationship to neighbors
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry cvc-hostd 442/udp

Primary use

Unknown — IANA publishes no protocol specification, RFC, or descriptive text beyond the bare service name; no primary source documents what cvc-hostd does

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=442

Other/unofficial uses

none documented in any primary source; unattributed speculation about a Cisco secure-channel or VM host/guest role circulates on secondary port-lookup sites but is not corroborated [Unknown]

Security implications

no CVE/NVD record found as of an August 2026 search; auditmypc.com's TCP-442 page carries a positive malware-indicator statement citing the Emerging Threats rule "ET MALWARE Win32/Ramnit Checkin" (C2 category, low activity); SANS ISC records ongoing low-volume scanning (threat level green) as of an August 2026 check

[Likely] — https://www.auditmypc.com/tcp-port-442.asp, https://isc.sans.edu/data/port/442

Typically seen on

Unknown — no vendor documentation, blog post, or forum thread names software binding to this port; community consensus across secondary ports-database sites is that the registration is formally held but practically unused

[Unknown] — https://www.speedguide.net/port.php?port=442
Analyst note
An open port 442 is statistically rare (nmap-services ~0.014% tcp) and has no documented legitimate current use; the one concrete security signal found is a Ramnit command-and-control detection signature, so treat a responsive 442/tcp as anomalous and worth investigating — do not assume a Cisco or VM host/guest function without further evidence.
[ 02 ] — Context

About port 442/udp.

Updated  ·  Confidence: Low

Port 442/udp carries cvc-hostd, an IANA-registered service name with no confirmed real-world software or protocol specification behind it. No credible source documents a legitimate application actively using this port, so an open 442/udp has no established reason to be reachable from the public internet and should be treated as anomalous rather than routine traffic.

IANA's Service Names and Port Numbers registry lists cvc-hostd as the current service name on both 442/tcp and 442/udp, assigned to Bill_Davidson. Both transports also retain the earlier "cvc_hostd" spelling as a now-historic alias entry — the registry's own text says it is "now historic, not usable for use with many common service discovery mechanisms." The Reference column is blank on every one of these rows; no RFC or specification is cited.

No RFC, vendor page, or software repository was found describing what cvc-hostd does or confirming actual protocol traffic. Aggregator and directory sites largely just restate the IANA name; one low-quality directory page's added claim that the port carries Cisco VM-host encryption traffic could not be corroborated elsewhere and is not adopted here. Real-world usage of 442/udp is effectively undocumented.

SANS Internet Storm Center's port-442 activity page, which aggregates TCP and UDP together, showed low but nonzero scanning as of an August 2026 check, with source-IP counts varying sharply day to day — consistent with routine opportunistic internet background noise rather than a targeted campaign against this specific port.

IANA assignment
cvc-hostd — description "cvc_hostd" (registry text: "IANA assigned this well-formed service name as a replacement for 'cvc_hostd'"); Reference column blank; Assignee [Bill_Davidson]; dual-registered 442/tcp + 442/udp, both transports also carrying the historic cvc_hostd alias
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry cvc-hostd 442/udp, cvc_hostd 442/udp
Range class
well-known (0–1023); source artifact labels this the "system" range [Confirmed] — this site's own tooling (port 442 entry)
Prevalence
nmap-services open-frequency 442/udp = 0.000774 (~0.077%); 442/tcp = 0.000138 (~0.014%) [Confirmed] — this site's own tooling
Related ports
442/tcp (dual registration, same cvc-hostd name and same historic cvc_hostd alias); sits among a run of individually-registered, unrelated legacy-era service names (440 sgcp, 441 decvms-sysmgt, 443 https) with no functional relationship to neighbors
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry cvc-hostd 442/tcp

Primary use

Unknown beyond the bare IANA label — no RFC, protocol specification, or confirmed software implementation describes what cvc-hostd does

[Unknown] — the IANA Service Name and Transport Protocol Port Number Registry cvc-hostd 442/udp

Other/unofficial uses

none corroborated as of an August 2026 search; a single low-quality directory page's claim linking the port to Cisco VM-host encryption traffic is uncorroborated elsewhere and not adopted [Unknown]

Security implications

no CVE recorded and no malware/trojan association documented as of an August 2026 search; SANS ISC shows low, day-to-day-variable background scan activity

[Likely] — https://isc.sans.edu/data/port/442

Typically seen on

Unknown as of an August 2026 search — no vendor or software attribution found [Unknown]

Analyst note
treat an open 442/udp as anomalous/unidentified traffic rather than assume legitimate cvc-hostd activity; no documented protocol, vendor, or software implementation exists for this service name.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
cvc_hostd UDP 0.08%
cvc_hostd TCP cvc-hostd 0.01%
IANA name
cvc-hostd
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.