539
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — Registered to a load-determination service with no documented modern implementation and a measured open-frequency of 0, so a response on 539/tcp is unexpected and should be investigated rather than treated as routine.
- // analyst note
- An open 539/tcp is statistically rare (measured open-frequency 0) and has no documented legitimate modern use — treat as anomalous and investigate.
- // if you see it open
- Essentially never legitimately open — the registered apertus-ldp service has no documented modern implementation and a measured open-frequency of 0. SANS ISC records routine internet-wide scan traffic on the port (as of an August 2026 check) with no associated CVE. Malware/Trojan association is Unknown; no confirmed verdict was found. A pentest page titled 'MSRPC - Port 135, 539' is a title mismatch (its content covers ports 135/593, not 539) and is not a valid MSRPC sighting on this port.
About port 539/tcp.
Port 539/tcp carries no documented modern service — it is registered to Apertus Technologies for a load-determination function with no active implementation on record — so it should not be exposed to the public internet and any response on it is worth investigating rather than treating as routine.
The IANA registry lists the service name apertus-ldp, description "Apertus Technologies Load Determination," in the System Ports range (0-1023), dual-registered on both TCP and UDP. Both the assignee and reference fields are blank, so no RFC or named vendor specification backs the protocol beyond the registry entry itself.
The measured nmap-services open-frequency for 539/tcp is exactly 0 (sampled, not observed open), while 539/udp measures roughly 0.0023. Threat-intelligence signature catalogs such as Juniper Threat Labs record the IANA registration under the apertus-ldp label but do not describe an active client-server implementation or recent traffic pattern.
SANS Internet Storm Center's per-port page for 539 shows routine internet-wide scan source IPs as of an August 2026 check, with no associated CVE and no user-submitted exploitation reports — consistent with opportunistic background scanning of a legacy, low-traffic system port rather than a targeted campaign. No community-sourced application or vendor product was found reporting legitimate use of 539/tcp. A pentesting reference page titled "MSRPC - Port 135, 539" is a mismatch: its body discusses ports 135 and 593, not 539, and should not be read as a sighting of MSRPC on this port.
- Exposure
- apertus-ldp has no documented modern legitimate implementation and a measured open-frequency of 0; classify as anomalous and investigate any response rather than treating it as routine service traffic.
- Scanning activity
- SANS ISC's port-539 page records ongoing internet-wide scan source IPs as of an August 2026 check, with no associated CVE or exploitation report.
- Malware association
- Unknown — no confirmed Trojan/virus association was established; a search snippet attributed to auditmypc.com surfaced only that site's generic template sentence, not a verdict, so no claim is made either way.
- Registry gaps
- the IANA assignee and reference fields are blank for both the TCP and UDP registrations, so no RFC or vendor specification is cited for the protocol.
- IANA assignment
apertus-ldp— "Apertus Technologies Load Determination"; reference (blank); assignee (blank); dual-registered 539/tcp + 539/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry apertus-ldp 539/tcp- Range class
- system/well-known (0-1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry apertus-ldp 539/tcp
- Prevalence
- nmap-services open-frequency 539/tcp = 0 (sampled, not observed open); 539/udp ≈ 0.002274 [Confirmed] — this site's own tooling
- Related ports
- 539/udp (dual registration, same service name); other rarely-used System Ports in this range
Primary use
officially assigned to Apertus Technologies for a load-determination service; no documented modern protocol spec or active implementation found beyond the registry entry
Other/unofficial uses
none documented; a pentest reference page titled "MSRPC - Port 135, 539" is a mismatch (its content covers ports 135/593, not 539) and should not be cited as an MSRPC sighting
Security implications
essentially never legitimately open; SANS ISC records routine scan traffic with no associated CVE; malware/Trojan association Unknown
Typically seen on
legacy/rare System Port assignment with no active implementation; an anomaly if seen open
- Analyst note
- An open 539/tcp is statistically rare (measured open-frequency 0) and has no documented legitimate modern use — treat as anomalous and investigate.
About port 539/udp.
Port 539/udp is registered with IANA under the name apertus-ldp ("Apertus Technologies Load Determination"), but no RFC, public protocol specification, or documented current software was found for it, so an open 539/udp should be treated as unknown/anomalous rather than expected on the public internet.
The IANA registry lists the service name, port number, and a bare description, with the assignee, contact, reference, and registration-date fields all blank. The port is dual-registered on TCP and UDP under the same name. There is no adjacent Apertus family: the neighbouring rows are gdomap at 538, uucp ("uucpd") at 540 and uucp-rlogin at 541, none of them an Apertus registration, so nothing in the registry supports reading 539 as part of a vendor block.
No technical specification describing the wire protocol was located, and no vendor documentation, blog post, or forum thread was found naming specific software that generates traffic on this port. Nothing beyond the bare IANA assignment could be established, so this entry asserts no usage for the port.
nmap-services open-frequency data places 539/udp at approximately 0.227% (0.002274) and 539/tcp at exactly 0.0 (sampled as never observed open in that corpus), consistent with an obscure, rarely-if-ever-deployed legacy vendor registration rather than an actively used service.
- Exposure
- Treat an open 539/udp as anomalous — no public protocol spec or known current software implements it, so unexpected traffic warrants investigation rather than being assumed benign.
- Malware association
- Not listed as malware/trojan-associated as of an August 2026 search — the SANS ISC port page for 539 carries empty trojan and CVE sections (https://isc.sans.edu/data/port/539).
- IANA reference
- No RFC or reference document is cited for this assignment; the registry's Reference field is blank.
- IANA assignment
apertus-ldp— "Apertus Technologies Load Determination"; reference (blank); assignee (blank); dual-registered 539/tcp + 539/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry apertus-ldp 539/udp- Range class
- well-known (0–1023) [Confirmed] — this site's own tooling
- Prevalence
- nmap-services open-frequency 539/udp ≈ 0.002274 (~0.23%); 539/tcp = 0.0 (sampled, not observed open) [Confirmed] — this site's own tooling
- Related ports
- 539/tcp (the same
apertus-ldpregistration on the other transport) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry apertus-ldp 539/tcp
Primary use
registered name for an Apertus Technologies "Load Determination" service; no public RFC or wire-protocol spec available [Confirmed registration / Unknown protocol details] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Other/unofficial uses
none documented; no community-sourced software sighting found
Security implications
no known protocol spec, no known deployed software, essentially unseen in practice; not listed as malware-associated as of an August 2026 search
Typically seen on
no documented typical deployment; an unexpected open 539/udp is an anomaly worth investigating [Unknown]
- Analyst note
- An open 539/udp has no documented legitimate deployment pattern; treat it as anomalous and worth investigating rather than assuming it is the registered Apertus service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| apertus-ldp | UDP | Apertus Technologies Load Determination | 0.23% |
| apertus-ldp | TCP | Apertus Technologies Load Determination | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.