Network port detail · UDP/TCP

531

Conference
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — Port 531 has no documented legitimate deployment and carries a legacy trojan association, so an open 531/tcp should be treated as anomalous and investigated rather than assumed benign.
// analyst note
treat any response on port 531 as anomalous — it has no legitimate documented deployment and carries a legacy trojan-port association.
// if you see it open
No mainstream software is documented using port 531 in practice. Legacy trojan-port compilations and SANS Internet Storm Center associate TCP 531 with the now-inactive trojans "Net666" and "Rasmin" (SANS ISC port-531 page). SANS ISC also records low-volume unsolicited scan traffic to the port, consistent with background internet noise rather than targeted exploitation. No CVE is recorded in the NVD for port 531 as of 2026-08.
[ 01 ] — Context

About port 531/tcp.

Updated  ·  Confidence: Medium  ·  3 sources  ·  How this page is checked

Port 531/tcp carries no documented mainstream service in practice: it is IANA-registered under the name "conference" for a generic chat protocol that never saw notable real-world deployment, so it should not be expected on the public internet and a response there is worth investigating as anomalous rather than treated as routine.

IANA's Service Name and Transport Protocol Port Number Registry lists 531 as dual-registered on TCP and UDP under the name "conference," description "chat." The registry carries no RFC or other reference for the assignment and no assignee is recorded, leaving the underlying protocol undefined beyond that one-word description.

No current mainstream application is documented as generating legitimate traffic on port 531. General port-reference sites describe it only as an officially assigned but essentially unimplemented registration; a few unverified, hedged mentions informally link it to older IRC-style or AOL-adjacent chat tools, but none of these are corroborated by a primary source.

The port does carry a legacy security footnote. Historical trojan-port compilations and SANS Internet Storm Center's port-531 tracking page associate TCP 531 with two now-inactive late-1990s/early-2000s trojans, "Net666" and "Rasmin." SANS ISC also shows continuing but low-volume unsolicited scan traffic to the port, consistent with routine internet background noise rather than active targeted exploitation.

Exposure
Port 531 has no legitimate documented service; an open 531/tcp on a host is anomalous and warrants investigation rather than being assumed benign.
Notable malware
Historically associated with the "Net666" and "Rasmin" trojans, both inactive as of an August 2026 search (SANS ISC port-531 page).
Scanning activity
SANS ISC records ongoing low-volume unsolicited scan traffic to port 531, consistent with background internet noise as of an August 2026 check.
No CVE
No CVE is recorded in the NVD for port 531 or its associated legacy trojans as of 2026-08.
IANA assignment
conference — "chat"; reference (blank — no RFC cited); assignee (none recorded); dual-registered 531/tcp + 531/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Prevalence
nmap-services open-frequency 531/tcp = 0 (sampled, not observed open in the corpus); 531/udp ≈ 0.000824 [Confirmed] — this site's own tooling
Related ports
no closely related "conference"/chat ports are documented in the registry alongside 531 [Unknown]

Primary use

registered "conference" chat service (IANA); no RFC cited and no primary evidence of real-world deployment

[Likely] — IANA registry, general port-reference sites

Other/unofficial uses

unverified, hedged legacy mentions of informal IRC-style/AOL-adjacent chat use; not corroborated by a primary source [Unknown]

Security implications

no mainstream software documented on this port; legacy association with the "Net666" and "Rasmin" trojans (both inactive); low-volume unsolicited scan noise; no CVE recorded

[Likely] — SANS ISC port-531 page

Typically seen on

not typically seen on production hosts; anomalous / possible legacy trojan artifact if open [Unknown]

Analyst note
treat any response on port 531 as anomalous — it has no legitimate documented deployment and carries a legacy trojan-port association.
[ 02 ] — Context

About port 531/udp.

Updated  ·  Confidence: Low  ·  4 sources  ·  How this page is checked

Port 531/udp carries the IANA-registered conference chat service; it is a legacy, essentially unused assignment that should never be exposed to the public internet, and an open 531/udp today is unusual enough to warrant investigation rather than routine acceptance.

IANA lists 531 for both tcp and udp under the service name conference with description "chat," a historical chat/conferencing assignment. No RFC reference is cited, and the Assignee field is blank. No current vendor implementation built around this registration could be identified.

Real-world adoption appears negligible. nmap-services measures 531/udp open-frequency at roughly 0.08% and 531/tcp at a sampled 0% — a real reading, not an absence of data. A community aggregator (WhatPortIs) hedges that AOL Instant Messenger (AIM) or IRC clients have "unofficially" used the port by convention, but that claim conflicts with IANA's own formal registration and is not vendor-confirmed.

As of an August 2026 check, SANS Internet Storm Center's port-531 page shows only modest scanning-source activity and a low overall threat indicator, with no CVEs recorded. The same page catalogues two trojan/malware family names historically associated with the port.

Exposure
Not designed for public internet exposure; the registered chat service saw negligible real deployment — nmap-services measures 531/udp at 0.000824 and 531/tcp at a sampled 0 — so an open 531/udp is anomalous rather than routine [Likely] — this site's own tooling
Notable threat listing
SANS ISC's port-531 aggregator page names the trojan/malware families "Net666" and "Rasmin" as historically catalogued against this port; this is an aggregator listing, not confirmation of an active campaign [Unknown] — https://isc.sans.edu/data/port/531
Scanning activity
As of an August 2026 check, SANS ISC shows modest scanning-source volume and a low overall threat-level indicator for the port, with no CVEs listed [Likely] — https://isc.sans.edu/data/port/531
IANA assignment
conference — "chat"; reference (blank — no RFC cited); assignee (blank); dual-registered 531/tcp + 531/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry conference 531/udp
Range class
well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry conference 531/udp
Prevalence
nmap-services open-frequency 531/udp ≈ 0.000824 (~0.08%); 531/tcp ≈ 0 (sampled, not observed open) [Confirmed] — this site's own tooling
Related ports
194/tcp (IRC); 5190/tcp (AOL Instant Messenger) — comparable legacy chat-protocol ports

Primary use

registered "conference" chat service; measured adoption is negligible, at 531/udp 0.000824 and 531/tcp a sampled 0

[Confirmed] — this site's own tooling

Other/unofficial uses

none corroborated. A community aggregator self-labels an AIM/IRC association as "assignment: unofficial / used by convention", but no primary source corroborates it, so nothing is asserted here — the same reading the DONE sibling 531/tcp publishes off the identical registry row

[Unknown] — https://whatportis.com/ports/531_aol-instant-messenger-irc

Security implications

SANS ISC catalogues the trojan families Net666 and Rasmin against this port historically; current scanning activity is low with no CVEs recorded as of an August 2026 check

[Unknown/Likely] — https://isc.sans.edu/data/port/531

Typically seen on

essentially unused; an open instance is anomalous and worth investigating

[Likely] — https://isc.sans.edu/data/port/531
Analyst note
A responsive 531/udp is statistically rare and not backed by any confirmed current application; treat it as a legacy relic, decoy, or possible trojan indicator rather than routine chat traffic.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
conference UDP chat 0.08%
conference TCP chat 0.00%
IANA name
conference
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.