481
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — The IANA 'ph' assignment on 481/tcp has no documented real-world deployment, no software reported using it, and negligible open-frequency in the nmap-services corpus, so a responsive 481/tcp warrants investigation rather than being treated as expected traffic.
- // analyst note
- an open 481/tcp has no confirmed legitimate association; investigate as an anomaly rather than assume routine service traffic.
- // if you see it open
- No CVE or named malware family is documented specifically for 481/tcp as of an August 2026 search. GRC's Port Authority entry lists no trojan/malware association. No software or vendor documentation was found reporting real-world use of this port, and open-frequency in the nmap-services corpus is negligible, so an open 481/tcp should be treated as anomalous and investigated rather than assumed routine.
About port 481/tcp.
Port 481/tcp carries no service with any confirmed real-world deployment: IANA registers it as ph ("Ph service") to Roland Hedberg, but no vendor, application, or protocol document ties actual traffic to this port, so an open 481/tcp is anomalous rather than expected and should not be treated as routine internet-facing traffic.
IANA registers 481 on both TCP and UDP under the service name ph, description "Ph service," assignee Roland_Hedberg, with a blank Reference field (no RFC cited) and no registration date recorded in the registry.
The name plausibly nods to the CCSO Nameserver ("Ph") directory-lookup protocol documented in RFC 2378, which Roland Hedberg co-authored. However, the customary/well-known port for CCSO Ph deployments is TCP 105 (registered as csnet-ns/cso-ns), not 481, and no source explains why a second ph entry exists at 481 or connects it to real CCSO Ph servers — treat this as a distinct, sparsely-documented assignment rather than confirmation of common CCSO Ph usage.
The repo's processed nmap-services artifact (this site's own tooling, built from nmap-services) records 481/tcp under the label dvs with description "ph" at open-frequency ≈0.000176, while 481/udp carries the label ph at ≈0.000445 — a naming mismatch between nmap-services' tcp/udp rows for this port number that is itself worth noting rather than resolving by guesswork.
No software, vendor documentation, blog post, or forum thread was found reporting real-world use of 481/tcp, and no CVE or named malware family is documented against it as of an August 2026 search.
- IANA assignment
ph— "Ph service"; reference (blank — no RFC cited); assignee Roland_Hedberg; dual-registered 481/tcp + 481/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ph 481/tcp; the IANA Service Name and Transport Protocol Port Number Registry ph 481/udp- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 481/tcp ≈0.000176 (labeled
dvs, description "ph"); 481/udp ≈0.000445 (labeledph) [Confirmed] — this site's own tooling (built from nmap-services); https://raw.githubusercontent.com/nmap/nmap/master/nmap-services - Related ports
- 105/tcp (csnet-ns/cso-ns, the customary CCSO Ph service port) [Likely] — https://tools.ietf.org/html/rfc2378
Primary use
no confirmed primary use; IANA's ph registration has no documented protocol specification or deployment history tied to port 481 specifically
Other/unofficial uses
possible (unconfirmed) nod to the CCSO Nameserver "Ph" directory protocol (RFC 2378, co-authored by the same Roland Hedberg), though that protocol's customary port is TCP 105, not 481
Security implications
no CVE or named malware family documented for 481/tcp as of an August 2026 search; GRC lists no trojan association
Typically seen on
no confirmed deployment pattern; not associated with any current mainstream software [Unknown]
- Analyst note
- an open 481/tcp has no confirmed legitimate association; investigate as an anomaly rather than assume routine service traffic.
About port 481/udp.
Port 481/udp carries no documented protocol: it is IANA-registered under the bare service name ph ("Ph service") with no RFC, specification, or vendor write-up describing what actually runs on it, so it should not be assumed safe to expose to the public internet and any observed traffic is unusual enough to warrant investigation rather than routine allowance.
The IANA registry confirms the assignment itself: service name ph, description "Ph service," assignee Roland Hedberg, dual-registered on both 481/tcp and 481/udp, with a blank Reference column — no RFC or other document is cited for the protocol's behavior.
The name plausibly nods to the CCSO Nameserver ("Ph") directory-lookup protocol documented in RFC 2378, "The CCSO Nameserver (Ph) Architecture," which Roland Hedberg co-authored (with Paul Pomes). That the 481 ph registration's assignee is the CCSO Ph architecture's own author, and that the registration carries that protocol's name and description, makes a connection likely rather than a bare name-string coincidence. RFC 2378 nonetheless specifies TCP port 105 (registered as csnet-ns/cso-ns) for the CCSO Ph service, not 481, and no source explains why a second ph entry exists at 481 or ties it to real CCSO Ph server deployments — so report the name-and-author link together with the unexplained port difference, rather than asserting either a confirmed identity or an unrelated coincidence.
No vendor documentation, blog post, or forum/support thread surfaced describing real-world software that sends or listens on 481/udp as of an August 2026 search. The repo's nmap-services-derived prevalence data records an open-frequency of 0.000445 (about 0.045% of scanned hosts) for 481/udp, confirming the port is rarely seen open but not explaining what answers when it is.
- IANA assignment
ph— "Ph service"; reference (blank — no RFC cited); assignee Roland Hedberg; dual-registered 481/tcp + 481/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ph 481/udp- Range class
- well-known (0–1023) [Confirmed] — port number 481 falls in the IANA system/well-known range
- Prevalence
- nmap-services open-frequency for 481/udp = 0.000445 (~0.0445%) [Confirmed] — this site's own tooling (built from nmap-services)
- Related ports
- 105/tcp (CCSO Nameserver "Ph"/Qi phonebook, registered as csnet-ns/cso-ns — the RFC 2378-specified port for the protocol this registration's name and author connect to) [Confirmed] — https://www.rfc-editor.org/rfc/rfc2378
Primary use
Unknown beyond the bare IANA label "Ph service" — no specification or vendor documentation found describing the protocol's actual behavior
Other/unofficial uses
Likely related to the CCSO Nameserver "Ph" phonebook protocol (RFC 2378) — the assignee, Roland Hedberg, co-authored that RFC and the registration carries the same name and description, but RFC 2378 specifies TCP/105 for the CCSO Ph service, not 481, and no source explains the port difference
Security implications
no CVE or malware association recorded as of an August 2026 search; no scanning-specific writeups found; exposure posture cannot be curated beyond "investigate if seen"
Typically seen on
Unknown — no sightings of specific hosts, vendors, or software found [Unknown]
- Analyst note
- A responsive 481/udp has no documented legitimate service behind it as of this research pass; its assignee's authorship of RFC 2378 makes a CCSO Ph connection likely, but the protocol's own specified port is 105, not 481, so treat 481/udp itself as unexplained rather than assume it runs the CCSO phonebook protocol.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ph | UDP | — | 0.04% |
| dvs | TCP | ph | 0.02% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.