447
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — IANA's DDM-Distributed File Management registration has no confirmed contemporary legitimate traffic, while the port's best-documented modern real-world use is TrickBot command-and-control, so a listener on 447/tcp should be treated as anomalous and investigated rather than assumed to be legitimate IBM DDM activity.
- // analyst note
- An open 447/tcp is statistically rare (nmap-services ~0.0138%) and has no confirmed legitimate current traffic — treat as anomalous and check for TrickBot-style encrypted C2 (self-signed TLS certificate) before assuming IBM DDM activity.
- // if you see it open
- IANA reserves 447/tcp for ddm-dfm, part of IBM's DDM architecture for remote file access on legacy IBM midrange systems (AS/400/iSeries/IBM i); no contemporary sighting of genuine DDM traffic on this port was found in this search. The port's most citable modern use is malicious: the TrickBot banking trojan is documented using TCP port 447 (alongside 443 and 449) for encrypted TLS/SSL command-and-control to self-signed-certificate servers (Palo Alto Networks Unit 42, dated 2019-11-08; corroborated by Gigamon, dated 2019-03-02). SANS Internet Storm Center's live tracker shows ongoing low-volume scanning of port 447 as of an August 2026 check. No CVE/NVD record specific to this port was found. Because no legitimate current traffic was confirmed and a documented malware C2 use exists, an open 447/tcp should be treated as anomalous and investigated rather than assumed to be legitimate IBM DDM traffic.
About port 447/tcp.
Port 447/tcp is IANA-registered as ddm-dfm for IBM's DDM-Distributed File Management protocol; no legitimate current traffic was confirmed here, and its most citable modern identity — TrickBot command-and-control — means it does not belong on the public internet. ddm-dfm is part of IBM's Distributed Data Management (DDM) family, historically used for remote file access between IBM midrange systems such as the AS/400, iSeries, System i, and IBM i.
IANA's registry lists 447/tcp and 447/udp as ddm-dfm, assignee and contact [Steven_Ritland], with a blank Reference field and no registration or modification date recorded. Two sibling DDM-family ports sit immediately adjacent: 446/tcp+udp (ddm-rdb, Remote Relational Database Access), whose Assignee and Contact fields are blank in the registry, and 448/tcp+udp (ddm-ssl, Remote DB Access Using Secure Sockets), also assigned to [Steven_Ritland].
Secondary port-lookup sites sometimes describe 447 using a neighboring DDM-family member's name (ddm-ssl or ddm-rdb) instead of the registry's own ddm-dfm string, but the primary IANA CSV is unambiguous: 447 is specifically DDM-Distributed File Management, distinct from the relational-database and SSL-secured variants on 446 and 448.
No contemporary sighting of genuine DDM traffic on this port was found in this search. The port's best-documented modern use is malicious: the TrickBot banking trojan is reported using TCP port 447 (alongside 443 and 449) for encrypted TLS/SSL command-and-control to self-signed-certificate servers, per Palo Alto Networks Unit 42 (dated 2019-11-08); Gigamon (dated 2019-03-02) corroborates the use of 447 and 449 specifically but does not name 443.
SANS Internet Storm Center's live tracker shows ongoing low-volume internet-wide scanning of port 447 as of an August 2026 check, consistent with routine background probing rather than a specific campaign. nmap-services open-frequency data puts 447/tcp at roughly 0.0138% and 447/udp at roughly 0.0675% — both rare readings consistent with the port's dormant registered use.
- IANA assignment
ddm-dfm— "DDM-Distributed File Management"; reference (blank — no RFC cited in IANA registry); assignee/contact [Steven_Ritland]; dual-registered 447/tcp + 447/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-dfm 447/tcp, ddm-dfm 447/udp- Range class
- well-known (0–1023); source artifact labels this the "system" range [Confirmed] — this site's own tooling (port 447 entry)
- Prevalence
- nmap-services open-frequency 447/tcp ≈ 0.000138 (~0.0138%); 447/udp ≈ 0.000675 (~0.0675%) [Confirmed] — this site's own tooling (port 447 entry)
- Related ports
- 446/tcp+udp
ddm-rdband 448/tcp+udpddm-ssl(same DDM family, same assignee); 449/tcpas-servermap(also named in TrickBot's C2 port set) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/tcp, ddm-ssl 448/tcp, as-servermap 449/tcp
Primary use
part of IBM's DDM (Distributed Data Management) architecture for remote file access on legacy IBM midrange systems (AS/400, iSeries, System i, IBM i); sibling registrations 446/tcp+udp (ddm-rdb) and 448/tcp+udp (ddm-ssl) sit immediately adjacent, same assignee
Other/unofficial uses
none documented as legitimate current traffic; secondary port-lookup sites sometimes mislabel 447 using a sibling DDM port's name (ddm-rdb/ddm-ssl) rather than the registry's own ddm-dfm string
Security implications
no contemporary sighting of legitimate DDM traffic found; TrickBot documented using 447/tcp (with 443, 449) for encrypted C2 to self-signed-cert servers; no CVE/NVD record specific to this port; SANS ISC shows ongoing low-volume scanning as of an August 2026 check [Likely] — https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-trickbot-infections/, https://blog.gigamon.com/2019/03/02/revisiting-prolific-crimeware-to-improve-network-detection-trickbot/
Typically seen on
no confirmed legitimate current deployments (historically IBM AS/400/iSeries/IBM i midrange DDM traffic per the registration); TrickBot-infected hosts calling out to encrypted C2
- Analyst note
- An open 447/tcp is statistically rare (nmap-services ~0.0138%) and has no confirmed legitimate current traffic — treat as anomalous and check for TrickBot-style encrypted C2 (self-signed TLS certificate) before assuming IBM DDM activity.
About port 447/udp.
Port 447/udp carries ddm-dfm, part of IBM's DDM (Distributed Data Management) family for remote file and database access; as a legacy mainframe/midrange protocol it has no documented reason to be reachable from the public internet and should stay confined to internal networks.
IANA registers 447 as ddm-dfm ("DDM-Distributed File Management") on both TCP and UDP, assignee Steven Ritland, with a blank Reference field — no RFC accompanies the entry on either transport. The two neighboring ports form the same IBM cluster: 446 is ddm-rdb (DDM-Remote Relational Database Access) and 448 is ddm-ssl (DDM-Remote DB Access Using Secure Sockets); 447 itself covers file management only.
DDM is an IBM protocol architecture for remote file and database access that predates modern web and application protocols, historically paired with mainframe and midrange systems such as AS/400 and z/OS and with DB2. It is rarely encountered on general-purpose networks today, and no vendor documentation, blog post, or forum thread from an August 2026 search identifies a specific modern application generating traffic on 447/udp.
Measured prevalence in the nmap-services scan corpus is low: an open-frequency of about 0.0675% on UDP, roughly five times the 0.0138% measured on TCP. SANS Internet Storm Center's port-activity tracker records port 447 (TCP and UDP combined) with only low-volume background scanning and a green threat level as of an August 2026 check, and no CVE or malware family is documented against the port.
- IANA assignment
ddm-dfm— "DDM-Distributed File Management"; reference (blank — no RFC cited); assignee[Steven_Ritland]; dual-registered 447/tcp + 447/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-dfm 447/udp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-dfm 447/udp
- Prevalence
- nmap-services open-frequency 447/udp ≈ 0.000675 (~0.0675%); 447/tcp ≈ 0.000138 (~0.0138%) [Confirmed] — this site's own tooling
- Related ports
- 446/ddm-rdb (DDM-Remote Relational Database Access), 448/ddm-ssl (DDM-Remote DB Access Using Secure Sockets) — same IBM DDM cluster [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/udp, ddm-ssl 448/udp
Primary use
DDM (Distributed Data Management), an IBM protocol family for remote file and database access, historically used with mainframe/midrange systems (AS/400, z/OS) and DB2; predates modern web/app protocols and is rarely seen on general-purpose networks today
Other/unofficial uses
Unknown, as of an August 2026 search — no vendor doc, blog, or forum thread identifies a modern application generating traffic on UDP 447; generic port-lookup aggregator pages (adminsub.net, tcp-udp-ports.com, ports.my-addr.com, wintelguy.com, speedguide.net, portdir.com) only restate the IANA ddm-dfm assignment with no independent usage evidence [Unknown]
Security implications
no CVE or named malware family documented as of an August 2026 search; SANS ISC records only low-volume background scanning (green threat level) for port 447 as of an August 2026 check
Typically seen on
legacy IBM mainframe/midrange DDM deployments (AS/400, z/OS, DB2); a responsive listener outside that context is atypical
- Analyst note
- ddm-dfm is a documented but legacy IBM DDM file-access service with no confirmed modern application usage and no known malware association; a listener reachable from the public internet is atypical and worth investigating, and it belongs alongside the paired 446/ddm-rdb and 448/ddm-ssl services on internal-only IBM DDM segments.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ddm-dfm | UDP | — | 0.07% |
| ddm-dfm | TCP | DDM-Distributed File Management | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.