528
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — custix has no documented public-facing implementation or widely-adopted use, so legitimate traffic on 528/tcp is plausible only within a specific vendor's private infrastructure and an open instance elsewhere is unusual.
- // analyst note
- An open port 528/tcp is statistically rare and has no documented public deployment — treat as an anomaly worth investigating rather than an expected service.
- // if you see it open
- No malware, trojan, or CVE association found as of an August 2026 search of NVD and general web search. The IANA Reference field is blank, so the underlying protocol is not publicly documented, limiting independent security review. Near-zero observed open-frequency means an unexpected open 528/tcp on a general-purpose host is unusual and worth investigating rather than assuming routine service.
About port 528/tcp.
Port 528/tcp carries no widely-deployed service; it is IANA-registered as custix ("Customer IXChange") but has no known vendor implementation, so it should not be exposed to the public internet and any traffic on it is unusual rather than routine.
IANA lists 528 as dual-registered on TCP and UDP for custix, assignee Ferdi_Ladeira, with a blank Reference field — no RFC or protocol specification is cited, so the actual wire protocol behind "Customer IXChange" is not documented publicly. The adjacent port 527/tcp is registered under the service name stx, with "Stock IXChange" as its description column, suggesting 528 belongs to a small, narrowly-scoped family of exchange-related registrations from the same assignee rather than a broadly adopted service.
No software, game client, or vendor product could be found named as generating traffic on this port, and no malware, trojan, or CVE association surfaced, as of an August 2026 search. Corpus prevalence data confirms the port is essentially never observed open in the wild.
Given the blank RFC reference, the absence of any documented implementation, and the near-zero observed open-frequency, port 528/tcp should be treated as a low-signal registration: legitimate use is plausible only inside a specific vendor's private exchange infrastructure, and an unexpected open 528/tcp on a general-purpose host is worth investigating rather than assumed benign.
- Exposure
- custix has no documented public-facing use case; treat any open 528/tcp as unexpected and investigate rather than assume routine service.
- Malware/CVE
- no malware, trojan, or CVE association found for 528/tcp as of an August 2026 search of NVD and general web search.
- Protocol documentation
- IANA's Reference field is blank for this registration, so the wire protocol is not publicly specified, which limits independent security assessment.
- IANA assignment
custix— "Customer IXChange"; reference blank; assignee Ferdi_Ladeira; dual-registered 528/tcp + 528/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry custix 528/tcp- Range class
- well-known/system (0–1023) [Confirmed]
- Registration date
- blank in the registry; the row carries a modification date of 2022-01-25 instead [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry custix 528/tcp
- Prevalence
- nmap-services open-frequency 528/tcp = 0.000013 (~0.0013%); 528/udp = 0.000329 [Confirmed] — this site's own tooling
- Related ports
- 527/tcp (
stx, description "Stock IXChange"; same assignee family)
Primary use
Customer IXChange per IANA registration; no RFC/protocol reference exists to document the actual behavior
Other/unofficial uses
none found as of an August 2026 search; no application, vendor product or game client is documented on this port [Unknown]
Security implications
no CVE or malware/trojan association found as of an August 2026 search; blank IANA reference limits independent protocol review [Likely]
Typically seen on
unknown; adjacent 527/tcp (stx, description "Stock IXChange") suggests a small family of exchange-protocol registrations from the same assignee
- Analyst note
- An open port 528/tcp is statistically rare and has no documented public deployment — treat as an anomaly worth investigating rather than an expected service.
About port 528/udp.
Port 528/udp carries custix ("Customer IXChange"), an IANA-registered system service with no published protocol specification and no confirmed real-world software behind it; it should not be treated as a port that belongs open to the public internet, and an unexplained response on it is worth investigating rather than assuming benign.
IANA registers custix jointly on 528/tcp and 528/udp, assignee Ferdi Ladeira, with the Registration Date column left blank and a Modification Date of 2022-01-25, and with the Reference column left blank — no RFC or other formal document defines the wire protocol. The description string "Customer IXChange" is the only public detail IANA carries for this assignment.
No community-sourced sighting of a specific application, vendor product, or service generating traffic on 528/udp turned up in web research. General port-lookup aggregator pages (SpeedGuide and similar) simply republish the IANA name and description without attributing it to any known software, so no traffic-source claim can be made beyond the bare registry entry.
The nmap-services open-frequency figure for 528/udp is 0.000329 (roughly 0.03% of scanned hosts), a low but nonzero reading from the sampled corpus — treated here as a measured figure rather than an absence. The companion 528/tcp row reads 0.000013. Neither figure identifies what is actually answering; both are consistent with an obscure, rarely-deployed system service.
- Exposure
- No documented protocol or known vendor deployment was found for
custix; treat 528/udp as a port that should not face the public internet, and investigate any unexpected response. - Malware association
- Unknown as of an August 2026 search — no port-528-specific malware or trojan finding, positive or negative, was sourced this pass; auditmypc.com's port-528 page did not return retrievable port-specific content.
- Scanning/exposure data
- Unknown — no Shodan/Censys-style scanning statistics or honeypot data specific to port 528 were found.
- IANA assignment
custix— "Customer IXChange"; reference (blank — no RFC cited); assignee Ferdi Ladeira; dual-registered 528/tcp + 528/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry custix 528/udp- Registration date
- blank in the registry; the row carries a modification date of 2022-01-25 instead [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry custix 528/udp
- Range class
- well-known/system (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry custix 528/udp
- Prevalence
- nmap-services open-frequency 528/udp = 0.000329 (~0.03%); 528/tcp = 0.000013 [Confirmed] — this site's own tooling
- Related ports
- 528/tcp (same
custixassignment, dual-registered) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry custix 528/tcp
Primary use
IANA-registered system port named "Customer IXChange"; no RFC or public protocol specification found describing wire-level behavior
Other/unofficial uses
Unknown — no community-sourced application sightings found for this port [Unknown]
Security implications
no documented protocol or known vendor software; essentially undocumented in practice, so an open 528/udp warrants investigation rather than assumption of benign use [Likely]
Malware/trojan association
Unknown as of an August 2026 search — no sourced finding either way [Unknown]
Typically seen on
Unknown — no confirmed deployment context found [Unknown]
- Analyst note
- An open 528/udp has no confirmed legitimate software behind it in available research; treat an unexpected response as worth investigating rather than routine.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| custix | UDP | Customer IXChange | 0.03% |
| custix | TCP | Customer IXChange | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.