449
Summary
- // typical exposure
- Internal-only — as-servermap is tied to IBM i (AS/400) client-server tooling by secondary sources and TrickBot has used this exact port for C2, so it has no documented reason to be reachable from the public internet.
- // common applications
- IBM i Access Client Solutions (ACS)IBM Client Access/400IBM Navigator for iIBM ODBC/JDBC/DRDA clients (e.g. DB2) Traffic on this port is most often IBM i (AS/400/iSeries) client-server tooling; secondary sources report IBM Access Client Solutions, Client Access/400, IBM Navigator for i, and ODBC/JDBC/DRDA-based clients using it, though this is not confirmed against a first-party IBM document.
- // analyst note
- An open 449/tcp is unusual outside an IBM i environment; because TrickBot has used this exact port for C2, an unexpected or internet-reachable listener warrants investigation rather than being assumed benign.
- // if you see it open
- No CVE or NVD record is associated with port 449 specifically as of an August 2026 search. auditmypc.com's four listed IDS rules for TCP/449 all key to a single 'MALWARE-CNC Win.Trojan.Trickbot self-signed certificate exchange' signature, consistent with (not separate from) the documented TrickBot C2 use below -- the site's own disclaimer states IDS-rule presence alone doesn't prove malicious traffic. A search-engine-generated claim that 449/tcp is used for Windows WMI could not be corroborated against Microsoft's own WMI documentation (TCP 135 plus a dynamic RPC range, not 449) and is not treated as fact.
About port 449/tcp.
Port 449/tcp carries as-servermap (AS Server Mapper), an IBM-linked IANA registration most commonly associated with IBM i (AS/400, iSeries, System i) client tooling; it should stay on internal or trusted networks rather than face the public internet.
IANA registers port 449 as as-servermap on both TCP and UDP, described only as "AS Server Mapper," with assignee and contact [Barbara_Foss] and a blank reference field — no RFC underlies this assignment. The three ports immediately below it, 446-448, are IBM's DDM (Distributed Data Management) family — ddm-rdb, ddm-dfm, ddm-ssl — an adjacent registration cluster consistent with an IBM AS/400 client-access suite, though a different individual is listed as assignee.
A secondary port-directory source, internet-security.com, explicitly names IBM i Access Client Solutions (ACS), the legacy IBM Client Access/400, IBM Navigator for i, and IBM ODBC/JDBC/DRDA-based tools (e.g. DB2 clients) as consumers of port 449; connected.app corroborates the general AS/400/iSeries/System i directory-lookup framing. IBM's own documentation pages (ibm.com/docs, ibm.com/support) returned HTTP 403 to direct fetch in this search, so the attribution rests on these secondary sources rather than a first-party IBM specification.
TrickBot malware has documented use of TCP/449 as a command-and-control channel: Microsoft's security research team documented TrickBot-infected hosts forwarding C2 traffic through compromised MikroTik routers via a NAT rule redirecting TCP/449 to port 80 on the C2 server, with 449 used alongside 443 as one of TrickBot's outbound C2 ports. This reinforces that an open, internet-reachable 449/tcp is not something to expect on a legitimate public-facing host.
- IANA assignment
as-servermap— "AS Server Mapper"; reference (blank — no RFC cited in IANA registry); assignee/contact [Barbara_Foss]; dual-registered 449/tcp + 449/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry as-servermap 449/tcp, as-servermap 449/udp- Range class
- well-known (0–1023); source artifact labels this the "system" range [Confirmed] — this site's own tooling (port 449 entry)
- Prevalence
- nmap-services open-frequency 449/tcp ≈ 0.000063 (~0.006%); 449/udp ≈ 0.000675 (~0.07%) [Confirmed] — this site's own tooling (port 449 entry)
- Related ports
- adjacent IBM DDM (Distributed Data Management) family 446/tcp+udp (
ddm-rdb), 447/tcp+udp (ddm-dfm), 448/tcp+udp (ddm-ssl) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/tcp, ddm-dfm 447/tcp, ddm-ssl 448/tcp
Primary use
attributed by secondary port-directory sources to IBM i (AS/400/iSeries/System i) client-server tooling — IBM i Access Client Solutions, legacy Client Access/400, IBM Navigator for i, and ODBC/JDBC/DRDA-based utilities; not independently confirmed against a first-party IBM document (IBM's docs/support pages returned HTTP 403 in this search)
Other/unofficial uses
TrickBot malware documented using TCP/449 as an outbound C2 port, including traffic forwarded through compromised MikroTik routers via a NAT rule (dst-port 449 -> 80) [Confirmed] — https://www.microsoft.com/en-us/security/blog/2022/03/16/uncovering-trickbots-use-of-iot-devices-in-command-and-control-infrastructure/, https://thehackernews.com/2022/03/trickbot-malware-abusing-hacked-iot.html
Security implications
no CVE/NVD record as of an August 2026 search; auditmypc.com's four IDS rules for TCP/449 all key to a single TrickBot self-signed-certificate-exchange signature rather than a separate finding; a search-engine claim of Windows WMI usage on this port is unverified and rejected [Confirmed(absence)/Likely] — https://www.auditmypc.com/tcp-port-449.asp, https://www.microsoft.com/en-us/security/blog/2022/03/16/uncovering-trickbots-use-of-iot-devices-in-command-and-control-infrastructure/
Typically seen on
IBM i (AS/400/iSeries) environments per secondary sources; also a documented TrickBot C2 port on malware-infected hosts [Likely] — https://internet-security.com/ports/port-449-TCP.html, https://www.microsoft.com/en-us/security/blog/2022/03/16/uncovering-trickbots-use-of-iot-devices-in-command-and-control-infrastructure/
- Analyst note
- An open 449/tcp is unusual outside an IBM i environment; because TrickBot has used this exact port for C2, an unexpected or internet-reachable listener warrants investigation rather than being assumed benign.
About port 449/udp.
Port 449/udp is registered with IANA as as-servermap (AS Server Mapper), but no publicly documented protocol specification, RFC, or confirmed real-world implementation exists for it — so it has no legitimate reason to be reachable from the public internet. The registration itself is solid; what actually generates traffic on it in practice is not.
IANA lists the assignee as Barbara Foss, with dual registration covering both 449/tcp and 449/udp, and no RFC or other reference document cited for either. The service name and a one-line description are the only substantive facts in the registry entry — there is no protocol document defining message formats or client/server behavior.
Several low-authority port-lookup aggregator sites claim port 449 is used for Microsoft WMI (Windows Management Instrumentation), but the claim is unsourced and conflicts with Microsoft's own documented WMI transport, which runs over DCOM/RPC on TCP port 135 plus a dynamically negotiated RPC port range. Treat the WMI association as unverified aggregator content, not a confirmed fact.
Telemetry backs up the obscurity: nmap-services records an open-frequency of about 0.0675% for 449/udp — far below common service ports — consistent with a name that is registered but almost never found open. SANS Internet Storm Center shows only routine, internet-wide background scanning on port 449, at a green (low) threat level, with no CVE or user reports logged as of an August 2026 check.
- IANA assignment
as-servermap— "AS Server Mapper"; reference (blank — no RFC cited in IANA registry); assignee Barbara Foss; dual-registered 449/tcp + 449/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry as-servermap 449/udp- Range class
- well-known (0–1023) [Confirmed] — this site's own tooling
- Prevalence
- nmap-services open-frequency for 449/udp ≈ 0.000675 (~0.0675%); 449/tcp ≈ 0.000063 (~0.0063%) [Confirmed] — this site's own tooling
- Related ports
- 449/tcp (same as-servermap registration, dual-registered); 135/tcp (actual DCOM/RPC endpoint-mapper port used by Microsoft WMI, sometimes mistakenly conflated with 449) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry as-servermap 449/tcp
Primary use
AS Server Mapper — no publicly documented protocol specification or RFC found; underlying protocol behavior is undocumented
Other/unofficial uses
none confirmed; a Microsoft WMI association appears on low-authority aggregator sites but is unsourced and contradicts Microsoft's documented WMI transport (DCOM/RPC on TCP 135 + dynamic RPC range)
Security implications
no documented protocol or confirmed application; SANS ISC shows only routine low-level internet-wide background scanning (green/low threat, no CVE or comments) as of an August 2026 check; no CVE recorded in the NVD as of August 2026; no malware/trojan association independently confirmed
Typically seen on
no specific OS, vendor, or software product confirmed by research; treat an open 449/udp as an anomaly to investigate rather than an expected service [Unknown]
- Analyst note
- Because as-servermap has no confirmed real-world implementation, treat an open 449/udp as worth investigating rather than assuming a benign service; do not rely on aggregator claims that attribute it to Microsoft WMI. [Likely]
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| as-servermap | UDP | AS Server Mapper | 0.07% |
| as-servermap | TCP | AS Server Mapper | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.