555
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No legitimate documented service is registered against this port and its chief notability is a legacy Windows backdoor/trojan association, so an open 555/tcp should be treated as anomalous rather than expected.
- // analyst note
- An open 555/tcp carries no legitimate documented service and has a legacy trojan association — investigate rather than assume benign use.
- // if you see it open
- No CVE is recorded in the NVD as of an August 2026 search tied specifically to port 555/tcp. Community/legacy security-reference lists (textfiles.com trojan port list; seclists.org 1999 thread) report several Windows 9x/ME-era backdoor and remote-access trojans historically using this port; these are legacy, community-sourced associations rather than confirmed current malware activity. No legitimate documented service is registered against the port, so an open 555/tcp warrants investigation.
About port 555.
Port 555/tcp is registered with IANA under the bare service name dsf, but no RFC or vendor specification documents what that protocol actually does; no legitimate current application is documented as routinely using it, so it should never be exposed to the public internet and a responsive 555/tcp is best treated as an anomaly worth investigating rather than an expected service.
The IANA registry entry for dsf is dual-registered on both TCP and UDP, and every optional column — description, assignee, and reference — is blank. There is no RFC citation and no named registrant behind the assignment, so the formal record establishes only that the name exists, not what it does.
The port's practical notability is almost entirely historical. Community security-reference and legacy port lists report several Windows 9x/ME-era backdoor and remote-access trojans as having used 555/tcp circa 1998–1999, including Phase Zero, Ini-Killer, Net Administrator, and Stealth Spy. These are hedged, community-sourced legacy associations rather than vendor-confirmed or currently active malware reports.
As of an August 2026 search, no CVE is recorded in the NVD tied specifically to port 555/tcp. The nmap-services open-frequency data puts 555/tcp at roughly 0.024% of scanned hosts (555/udp at roughly 0.033%), consistent with a port that is rarely open and rarely legitimate when it is.
- Malware history
- legacy Windows 9x/ME-era backdoor/RAT trojans (Phase Zero, Ini-Killer, Net Administrator, Stealth Spy) are reported on community port-reference lists as having used this port circa 1998–1999; these are legacy, community-sourced associations, not confirmed current activity.
- Recommendation
- treat an open 555/tcp as a signal to investigate rather than a normal finding — verify the actual listening process before assuming it is benign.
- IANA assignment
dsf— description, assignee, and reference all blank; dual-registered 555/tcp + 555/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry dsf 555/tcp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry dsf 555/tcp
- Prevalence
- nmap-services open-frequency 555/tcp ≈ 0.000238 (~0.024%); 555/udp ≈ 0.000329 (~0.033%) [Confirmed] — this site's own tooling
- Related ports
- no specific cluster identified; see the
/port/hub [Unknown]
Primary use
no documented protocol semantics beyond the registered name; no RFC or vendor spec found
Other/unofficial uses
reported historical use by 1998–99-era Windows backdoor/RAT trojans (Phase Zero, Ini-Killer, Net Administrator, Stealth Spy)
Security implications
no CVE tied to the port as of an August 2026 NVD search; legacy trojan-list association only
Typically seen on
legacy Windows 9x/ME hosts historically; otherwise an anomaly [Likely]
- Analyst note
- An open 555/tcp carries no legitimate documented service and has a legacy trojan association — investigate rather than assume benign use.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dsf | UDP | — | 0.03% |
| dsf | TCP | — | 0.02% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.