Network port detail · UDP/TCP

456

Macon-tcp
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No documented legitimate service exists for this port beyond a bare IANA name token, and legacy security references tie it to the Hackers Paradise backdoor, so a responsive 456/tcp should be treated as anomalous rather than routine.
// common applications
Hackers Paradise (legacy Windows trojan, Traffic on this port is most often unexplained by any legitimate service; legacy security references have reported the Hackers Paradise Windows backdoor/trojan using it (one source instead names it Masters Paradise), and current SANS ISC data shows only low-level ambient scanning rather than active exploitation.
// analyst note
An open port 456/tcp is statistically rare, has no documented legitimate protocol, and carries a legacy backdoor association ("Hackers Paradise"); treat as anomalous and investigate rather than assume benign use.
// if you see it open
No legitimate documented service exists for this port beyond the bare IANA name token. Legacy/community security references (SANS ISC, adminsub.net, older trojan-port compilations) consistently tie TCP 456 to the "Hackers Paradise" Windows backdoor/RAT; one vendor KB page instead names "Masters Paradise," an unresolved naming discrepancy. SANS ISC scanning-activity data as of an August 2026 search showed only low-level ambient background scan traffic, not a named or dated campaign.
[ 01 ] — Context

About port 456/tcp.

Updated  ·  Confidence: Medium

Port 456/tcp has no documented legitimate modern service — IANA lists only the bare name token "macon-tcp" with no protocol description or RFC — so it should not be exposed to the public internet, and an open 456/tcp is best treated as anomalous rather than routine.

The IANA registration itself is real but thin: 456/tcp is registered as "macon-tcp" (paired with "macon-udp" on 456/udp), assignee [Yoshinobu_Inoue], with a blank Reference field and no registration date shown on the current registry page. No RFC or vendor specification describing an actual "MACON" protocol was found, and no current, actively-maintained legitimate software was located in an August 2026 web search claiming this port.

Instead, port 456/tcp is better known in security-community references as a legacy Windows backdoor port. Several legacy port-list and security-reference sites — SANS Internet Storm Center's port page, adminsub.net's TCP/UDP port finder, and older trojan-port compilation blogs/textfiles — consistently associate TCP 456 with "Hackers Paradise," a remote-access trojan from the late-1990s/early-2000s era. One vendor knowledge-base page instead labels the port "Masters Paradise," which conflicts with the majority naming across other sources and is flagged here as an unresolved discrepancy rather than silently resolved.

SANS ISC's port-456 activity page, checked in an August 2026 search, showed only low-level ambient internet background scanning — single-digit-to-teens hit counts from scattered source IPs — consistent with routine opportunistic mass scanning rather than any named or dated campaign.

IANA assignment
macon-tcp (456/tcp), dual-registered with macon-udp (456/udp); no description beyond the name token; Reference field blank; assignee [Yoshinobu_Inoue] [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry macon-tcp 456/tcp
Range class
system/well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry macon-tcp 456/tcp
Prevalence
nmap-services open-frequency 456/tcp = 0.00005 (~0.005%); 456/udp = 0.000494 (~0.049%), measured directly from the repo artifact [Confirmed] — this site's own tooling
Related ports
456/udp (paired IANA registration, "macon-udp"); no other closely related documented cluster was found for this specific port [Confirmed for the 456/udp pairing; Unknown beyond that] — the IANA Service Name and Transport Protocol Port Number Registry macon-udp 456/udp

Primary use

No documented application-layer protocol exists for "macon-tcp" beyond the bare IANA name assignment; no RFC or vendor spec found [Confirmed absence, as of an August 2026 search] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

Legacy/community security references associate TCP 456 with the "Hackers Paradise" Windows backdoor/remote-access trojan (late 1990s–2000s); one source instead names "Masters Paradise" (unresolved discrepancy) [Likely] — https://isc.sans.edu/data/port/456, https://www.adminsub.net/tcp-udp-port-finder/hackersparadise, https://kb.eventtracker.com/evtpass/evtpages/PortNo_456_MastersParadise_55320.asp

Security implications

essentially never legitimately open; historical trojan association ("Hackers Paradise"/possibly "Masters Paradise"); observed scanning is low-level ambient noise, not a dated campaign, as of an August 2026 search

[Likely] — https://isc.sans.edu/data/port/456

Typically seen on

no known legitimate hosts identified; an open 456/tcp is an anomaly, best investigated as a possible backdoor artifact or decoy [Likely]

Analyst note
An open port 456/tcp is statistically rare, has no documented legitimate protocol, and carries a legacy backdoor association ("Hackers Paradise"); treat as anomalous and investigate rather than assume benign use.
[ 02 ] — Context

About port 456/udp.

Updated  ·  Confidence: Low

Port 456/udp carries the IANA-registered service macon-udp, but no publicly documented protocol specification or application describes what MACON actually does, so this port has no confirmed legitimate reason to face the public internet and should be treated as internal-only or anomalous pending further identification.

The IANA registry lists 456/udp as macon-udp (description "macon"), with 456/tcp separately registered as macon-tcp under the same assignee and contact, Yoshinobu_Inoue. The Reference column is blank in both rows — no RFC is cited — and no registration or modification date is recorded.

Beyond the bare service-name registration, the MACON protocol's actual purpose is undocumented. Third-party port-lookup aggregators such as SpeedGuide and my-addr.com simply restate the IANA entry rather than describing observed real-world software, so no specific application can be credited with generating traffic on this port.

The sibling TCP port carries a historic "HackersParadise" trojan tag in SANS Internet Storm Center's port-456 breakdown, but that source applies the tag only to the TCP side; the UDP side (macon-udp) carries no such tag there, and auditmypc.com's UDP-specific page records no malware/IDS-ruleset match for 456/udp.

SANS ISC's live port-456 attack-activity page (TCP and UDP combined) shows ongoing low-volume opportunistic internet scanning as of an August 2026 check, consistent with generic background noise rather than a targeted campaign. nmap-services measures 456/udp's open-frequency at 0.000494 (~0.0494%), meaning it is almost never seen open in real-world scans.

IANA assignment
macon-udp — "macon"; reference (blank — no RFC cited); assignee/contact Yoshinobu_Inoue; dual-registered alongside 456/tcp (macon-tcp, same assignee) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry macon-udp 456/udp
Range class
well-known (0–1023) [Confirmed] — this site's own tooling
Prevalence
nmap-services open-frequency 456/udp = 0.000494 (~0.0494%); sibling 456/tcp = 0.00005 (~0.005%) [Confirmed] — this site's own tooling
Related ports
456/tcp (macon-tcp, sibling registration, same assignee)

Primary use

Unknown — no independent technical description of the MACON protocol found beyond the IANA service-name registration [Unknown]

Other/unofficial uses

none documented; port-lookup aggregators (SpeedGuide, my-addr.com) merely restate the IANA registration rather than reporting observed software [Unknown] — https://www.speedguide.net/port.php?port=456, http://ports.my-addr.com/tcp_port-udp_port-application-and-description.php?port=456

Security implications

sibling TCP port carries a historic "HackersParadise" trojan tag in SANS ISC's breakdown, not extended to the UDP side; low-volume opportunistic scanning observed as of August 2026; auditmypc.com records no malware/IDS match for 456/udp specifically

[Likely] — https://isc.sans.edu/data/port/456, https://www.auditmypc.com/udp-port-456.asp

Typically seen on

no documented legitimate deployment; anomalous if seen [Unknown]

Analyst note
An open 456/udp has no confirmed legitimate use — treat as anomalous, verify against the host's actual role, and cross-check the TCP sibling before dismissing as background noise.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
macon UDP 0.05%
macon TCP macon-tcp 0.01%
IANA name
macon-tcp
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.