531
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — Port 531 has no documented legitimate deployment and carries a legacy trojan association, so an open 531/tcp should be treated as anomalous and investigated rather than assumed benign.
- // analyst note
- treat any response on port 531 as anomalous — it has no legitimate documented deployment and carries a legacy trojan-port association.
- // if you see it open
- No mainstream software is documented using port 531 in practice. Legacy trojan-port compilations and SANS Internet Storm Center associate TCP 531 with the now-inactive trojans "Net666" and "Rasmin" (SANS ISC port-531 page). SANS ISC also records low-volume unsolicited scan traffic to the port, consistent with background internet noise rather than targeted exploitation. No CVE is recorded in the NVD for port 531 as of 2026-08.
About port 531/tcp.
Port 531/tcp carries no documented mainstream service in practice: it is IANA-registered under the name "conference" for a generic chat protocol that never saw notable real-world deployment, so it should not be expected on the public internet and a response there is worth investigating as anomalous rather than treated as routine.
IANA's Service Name and Transport Protocol Port Number Registry lists 531 as dual-registered on TCP and UDP under the name "conference," description "chat." The registry carries no RFC or other reference for the assignment and no assignee is recorded, leaving the underlying protocol undefined beyond that one-word description.
No current mainstream application is documented as generating legitimate traffic on port 531. General port-reference sites describe it only as an officially assigned but essentially unimplemented registration; a few unverified, hedged mentions informally link it to older IRC-style or AOL-adjacent chat tools, but none of these are corroborated by a primary source.
The port does carry a legacy security footnote. Historical trojan-port compilations and SANS Internet Storm Center's port-531 tracking page associate TCP 531 with two now-inactive late-1990s/early-2000s trojans, "Net666" and "Rasmin." SANS ISC also shows continuing but low-volume unsolicited scan traffic to the port, consistent with routine internet background noise rather than active targeted exploitation.
- Exposure
- Port 531 has no legitimate documented service; an open 531/tcp on a host is anomalous and warrants investigation rather than being assumed benign.
- Notable malware
- Historically associated with the "Net666" and "Rasmin" trojans, both inactive as of an August 2026 search (SANS ISC port-531 page).
- Scanning activity
- SANS ISC records ongoing low-volume unsolicited scan traffic to port 531, consistent with background internet noise as of an August 2026 check.
- No CVE
- No CVE is recorded in the NVD for port 531 or its associated legacy trojans as of 2026-08.
- IANA assignment
conference— "chat"; reference (blank — no RFC cited); assignee (none recorded); dual-registered 531/tcp + 531/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Prevalence
- nmap-services open-frequency 531/tcp = 0 (sampled, not observed open in the corpus); 531/udp ≈ 0.000824 [Confirmed] — this site's own tooling
- Related ports
- no closely related "conference"/chat ports are documented in the registry alongside 531 [Unknown]
Primary use
registered "conference" chat service (IANA); no RFC cited and no primary evidence of real-world deployment
Other/unofficial uses
unverified, hedged legacy mentions of informal IRC-style/AOL-adjacent chat use; not corroborated by a primary source [Unknown]
Security implications
no mainstream software documented on this port; legacy association with the "Net666" and "Rasmin" trojans (both inactive); low-volume unsolicited scan noise; no CVE recorded
Typically seen on
not typically seen on production hosts; anomalous / possible legacy trojan artifact if open [Unknown]
- Analyst note
- treat any response on port 531 as anomalous — it has no legitimate documented deployment and carries a legacy trojan-port association.
About port 531/udp.
Port 531/udp carries the IANA-registered conference chat service; it is a legacy, essentially unused assignment that should never be exposed to the public internet, and an open 531/udp today is unusual enough to warrant investigation rather than routine acceptance.
IANA lists 531 for both tcp and udp under the service name conference with description "chat," a historical chat/conferencing assignment. No RFC reference is cited, and the Assignee field is blank. No current vendor implementation built around this registration could be identified.
Real-world adoption appears negligible. nmap-services measures 531/udp open-frequency at roughly 0.08% and 531/tcp at a sampled 0% — a real reading, not an absence of data. A community aggregator (WhatPortIs) hedges that AOL Instant Messenger (AIM) or IRC clients have "unofficially" used the port by convention, but that claim conflicts with IANA's own formal registration and is not vendor-confirmed.
As of an August 2026 check, SANS Internet Storm Center's port-531 page shows only modest scanning-source activity and a low overall threat indicator, with no CVEs recorded. The same page catalogues two trojan/malware family names historically associated with the port.
- Exposure
- Not designed for public internet exposure; the registered chat service saw negligible real deployment — nmap-services measures 531/udp at 0.000824 and 531/tcp at a sampled 0 — so an open 531/udp is anomalous rather than routine [Likely] — this site's own tooling
- Notable threat listing
- SANS ISC's port-531 aggregator page names the trojan/malware families "Net666" and "Rasmin" as historically catalogued against this port; this is an aggregator listing, not confirmation of an active campaign [Unknown] — https://isc.sans.edu/data/port/531
- Scanning activity
- As of an August 2026 check, SANS ISC shows modest scanning-source volume and a low overall threat-level indicator for the port, with no CVEs listed [Likely] — https://isc.sans.edu/data/port/531
- IANA assignment
conference— "chat"; reference (blank — no RFC cited); assignee (blank); dual-registered 531/tcp + 531/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry conference 531/udp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry conference 531/udp
- Prevalence
- nmap-services open-frequency 531/udp ≈ 0.000824 (~0.08%); 531/tcp ≈ 0 (sampled, not observed open) [Confirmed] — this site's own tooling
- Related ports
- 194/tcp (IRC); 5190/tcp (AOL Instant Messenger) — comparable legacy chat-protocol ports
Primary use
registered "conference" chat service; measured adoption is negligible, at 531/udp 0.000824 and 531/tcp a sampled 0
Other/unofficial uses
none corroborated. A community aggregator self-labels an AIM/IRC association as "assignment: unofficial / used by convention", but no primary source corroborates it, so nothing is asserted here — the same reading the DONE sibling 531/tcp publishes off the identical registry row
Security implications
SANS ISC catalogues the trojan families Net666 and Rasmin against this port historically; current scanning activity is low with no CVEs recorded as of an August 2026 check
Typically seen on
essentially unused; an open instance is anomalous and worth investigating
- Analyst note
- A responsive 531/udp is statistically rare and not backed by any confirmed current application; treat it as a legacy relic, decoy, or possible trojan indicator rather than routine chat traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| conference | UDP | chat | 0.08% |
| conference | TCP | chat | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.