Network port detail · UDP/TCP

447

Ddm-dfm
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — IANA's DDM-Distributed File Management registration has no confirmed contemporary legitimate traffic, while the port's best-documented modern real-world use is TrickBot command-and-control, so a listener on 447/tcp should be treated as anomalous and investigated rather than assumed to be legitimate IBM DDM activity.
// analyst note
An open 447/tcp is statistically rare (nmap-services ~0.0138%) and has no confirmed legitimate current traffic — treat as anomalous and check for TrickBot-style encrypted C2 (self-signed TLS certificate) before assuming IBM DDM activity.
// if you see it open
IANA reserves 447/tcp for ddm-dfm, part of IBM's DDM architecture for remote file access on legacy IBM midrange systems (AS/400/iSeries/IBM i); no contemporary sighting of genuine DDM traffic on this port was found in this search. The port's most citable modern use is malicious: the TrickBot banking trojan is documented using TCP port 447 (alongside 443 and 449) for encrypted TLS/SSL command-and-control to self-signed-certificate servers (Palo Alto Networks Unit 42, dated 2019-11-08; corroborated by Gigamon, dated 2019-03-02). SANS Internet Storm Center's live tracker shows ongoing low-volume scanning of port 447 as of an August 2026 check. No CVE/NVD record specific to this port was found. Because no legitimate current traffic was confirmed and a documented malware C2 use exists, an open 447/tcp should be treated as anomalous and investigated rather than assumed to be legitimate IBM DDM traffic.
[ 01 ] — Context

About port 447/tcp.

Updated  ·  Confidence: Medium

Port 447/tcp is IANA-registered as ddm-dfm for IBM's DDM-Distributed File Management protocol; no legitimate current traffic was confirmed here, and its most citable modern identity — TrickBot command-and-control — means it does not belong on the public internet. ddm-dfm is part of IBM's Distributed Data Management (DDM) family, historically used for remote file access between IBM midrange systems such as the AS/400, iSeries, System i, and IBM i.

IANA's registry lists 447/tcp and 447/udp as ddm-dfm, assignee and contact [Steven_Ritland], with a blank Reference field and no registration or modification date recorded. Two sibling DDM-family ports sit immediately adjacent: 446/tcp+udp (ddm-rdb, Remote Relational Database Access), whose Assignee and Contact fields are blank in the registry, and 448/tcp+udp (ddm-ssl, Remote DB Access Using Secure Sockets), also assigned to [Steven_Ritland].

Secondary port-lookup sites sometimes describe 447 using a neighboring DDM-family member's name (ddm-ssl or ddm-rdb) instead of the registry's own ddm-dfm string, but the primary IANA CSV is unambiguous: 447 is specifically DDM-Distributed File Management, distinct from the relational-database and SSL-secured variants on 446 and 448.

No contemporary sighting of genuine DDM traffic on this port was found in this search. The port's best-documented modern use is malicious: the TrickBot banking trojan is reported using TCP port 447 (alongside 443 and 449) for encrypted TLS/SSL command-and-control to self-signed-certificate servers, per Palo Alto Networks Unit 42 (dated 2019-11-08); Gigamon (dated 2019-03-02) corroborates the use of 447 and 449 specifically but does not name 443.

SANS Internet Storm Center's live tracker shows ongoing low-volume internet-wide scanning of port 447 as of an August 2026 check, consistent with routine background probing rather than a specific campaign. nmap-services open-frequency data puts 447/tcp at roughly 0.0138% and 447/udp at roughly 0.0675% — both rare readings consistent with the port's dormant registered use.

IANA assignment
ddm-dfm — "DDM-Distributed File Management"; reference (blank — no RFC cited in IANA registry); assignee/contact [Steven_Ritland]; dual-registered 447/tcp + 447/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-dfm 447/tcp, ddm-dfm 447/udp
Range class
well-known (0–1023); source artifact labels this the "system" range [Confirmed] — this site's own tooling (port 447 entry)
Prevalence
nmap-services open-frequency 447/tcp ≈ 0.000138 (~0.0138%); 447/udp ≈ 0.000675 (~0.0675%) [Confirmed] — this site's own tooling (port 447 entry)
Related ports
446/tcp+udp ddm-rdb and 448/tcp+udp ddm-ssl (same DDM family, same assignee); 449/tcp as-servermap (also named in TrickBot's C2 port set) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/tcp, ddm-ssl 448/tcp, as-servermap 449/tcp

Primary use

part of IBM's DDM (Distributed Data Management) architecture for remote file access on legacy IBM midrange systems (AS/400, iSeries, System i, IBM i); sibling registrations 446/tcp+udp (ddm-rdb) and 448/tcp+udp (ddm-ssl) sit immediately adjacent, same assignee

[Likely] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/tcp, ddm-ssl 448/tcp

Other/unofficial uses

none documented as legitimate current traffic; secondary port-lookup sites sometimes mislabel 447 using a sibling DDM port's name (ddm-rdb/ddm-ssl) rather than the registry's own ddm-dfm string

[Likely] — https://www.speedguide.net/port.php?port=447

Security implications

no contemporary sighting of legitimate DDM traffic found; TrickBot documented using 447/tcp (with 443, 449) for encrypted C2 to self-signed-cert servers; no CVE/NVD record specific to this port; SANS ISC shows ongoing low-volume scanning as of an August 2026 check [Likely] — https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-trickbot-infections/, https://blog.gigamon.com/2019/03/02/revisiting-prolific-crimeware-to-improve-network-detection-trickbot/

Typically seen on

no confirmed legitimate current deployments (historically IBM AS/400/iSeries/IBM i midrange DDM traffic per the registration); TrickBot-infected hosts calling out to encrypted C2

[Likely] — https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-trickbot-infections/
Analyst note
An open 447/tcp is statistically rare (nmap-services ~0.0138%) and has no confirmed legitimate current traffic — treat as anomalous and check for TrickBot-style encrypted C2 (self-signed TLS certificate) before assuming IBM DDM activity.
[ 02 ] — Context

About port 447/udp.

Updated  ·  Confidence: Low

Port 447/udp carries ddm-dfm, part of IBM's DDM (Distributed Data Management) family for remote file and database access; as a legacy mainframe/midrange protocol it has no documented reason to be reachable from the public internet and should stay confined to internal networks.

IANA registers 447 as ddm-dfm ("DDM-Distributed File Management") on both TCP and UDP, assignee Steven Ritland, with a blank Reference field — no RFC accompanies the entry on either transport. The two neighboring ports form the same IBM cluster: 446 is ddm-rdb (DDM-Remote Relational Database Access) and 448 is ddm-ssl (DDM-Remote DB Access Using Secure Sockets); 447 itself covers file management only.

DDM is an IBM protocol architecture for remote file and database access that predates modern web and application protocols, historically paired with mainframe and midrange systems such as AS/400 and z/OS and with DB2. It is rarely encountered on general-purpose networks today, and no vendor documentation, blog post, or forum thread from an August 2026 search identifies a specific modern application generating traffic on 447/udp.

Measured prevalence in the nmap-services scan corpus is low: an open-frequency of about 0.0675% on UDP, roughly five times the 0.0138% measured on TCP. SANS Internet Storm Center's port-activity tracker records port 447 (TCP and UDP combined) with only low-volume background scanning and a green threat level as of an August 2026 check, and no CVE or malware family is documented against the port.

IANA assignment
ddm-dfm — "DDM-Distributed File Management"; reference (blank — no RFC cited); assignee [Steven_Ritland]; dual-registered 447/tcp + 447/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-dfm 447/udp
Range class
well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-dfm 447/udp
Prevalence
nmap-services open-frequency 447/udp ≈ 0.000675 (~0.0675%); 447/tcp ≈ 0.000138 (~0.0138%) [Confirmed] — this site's own tooling
Related ports
446/ddm-rdb (DDM-Remote Relational Database Access), 448/ddm-ssl (DDM-Remote DB Access Using Secure Sockets) — same IBM DDM cluster [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/udp, ddm-ssl 448/udp

Primary use

DDM (Distributed Data Management), an IBM protocol family for remote file and database access, historically used with mainframe/midrange systems (AS/400, z/OS) and DB2; predates modern web/app protocols and is rarely seen on general-purpose networks today

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=8

Other/unofficial uses

Unknown, as of an August 2026 search — no vendor doc, blog, or forum thread identifies a modern application generating traffic on UDP 447; generic port-lookup aggregator pages (adminsub.net, tcp-udp-ports.com, ports.my-addr.com, wintelguy.com, speedguide.net, portdir.com) only restate the IANA ddm-dfm assignment with no independent usage evidence [Unknown]

Security implications

no CVE or named malware family documented as of an August 2026 search; SANS ISC records only low-volume background scanning (green threat level) for port 447 as of an August 2026 check

[Likely] — https://isc.sans.edu/data/port/447

Typically seen on

legacy IBM mainframe/midrange DDM deployments (AS/400, z/OS, DB2); a responsive listener outside that context is atypical

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=8
Analyst note
ddm-dfm is a documented but legacy IBM DDM file-access service with no confirmed modern application usage and no known malware association; a listener reachable from the public internet is atypical and worth investigating, and it belongs alongside the paired 446/ddm-rdb and 448/ddm-ssl services on internal-only IBM DDM segments.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ddm-dfm UDP 0.07%
ddm-dfm TCP DDM-Distributed File Management 0.01%
IANA name
ddm-dfm
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.