Network port detail · UDP/TCP

555

Dsf
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No legitimate documented service is registered against this port and its chief notability is a legacy Windows backdoor/trojan association, so an open 555/tcp should be treated as anomalous rather than expected.
// analyst note
An open 555/tcp carries no legitimate documented service and has a legacy trojan association — investigate rather than assume benign use.
// if you see it open
No CVE is recorded in the NVD as of an August 2026 search tied specifically to port 555/tcp. Community/legacy security-reference lists (textfiles.com trojan port list; seclists.org 1999 thread) report several Windows 9x/ME-era backdoor and remote-access trojans historically using this port; these are legacy, community-sourced associations rather than confirmed current malware activity. No legitimate documented service is registered against the port, so an open 555/tcp warrants investigation.
[ 01 ] — Context

About port 555.

Updated  ·  Confidence: Low  ·  4 sources  ·  How this page is checked

Port 555/tcp is registered with IANA under the bare service name dsf, but no RFC or vendor specification documents what that protocol actually does; no legitimate current application is documented as routinely using it, so it should never be exposed to the public internet and a responsive 555/tcp is best treated as an anomaly worth investigating rather than an expected service.

The IANA registry entry for dsf is dual-registered on both TCP and UDP, and every optional column — description, assignee, and reference — is blank. There is no RFC citation and no named registrant behind the assignment, so the formal record establishes only that the name exists, not what it does.

The port's practical notability is almost entirely historical. Community security-reference and legacy port lists report several Windows 9x/ME-era backdoor and remote-access trojans as having used 555/tcp circa 1998–1999, including Phase Zero, Ini-Killer, Net Administrator, and Stealth Spy. These are hedged, community-sourced legacy associations rather than vendor-confirmed or currently active malware reports.

As of an August 2026 search, no CVE is recorded in the NVD tied specifically to port 555/tcp. The nmap-services open-frequency data puts 555/tcp at roughly 0.024% of scanned hosts (555/udp at roughly 0.033%), consistent with a port that is rarely open and rarely legitimate when it is.

Malware history
legacy Windows 9x/ME-era backdoor/RAT trojans (Phase Zero, Ini-Killer, Net Administrator, Stealth Spy) are reported on community port-reference lists as having used this port circa 1998–1999; these are legacy, community-sourced associations, not confirmed current activity.
Recommendation
treat an open 555/tcp as a signal to investigate rather than a normal finding — verify the actual listening process before assuming it is benign.
IANA assignment
dsf — description, assignee, and reference all blank; dual-registered 555/tcp + 555/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry dsf 555/tcp
Range class
well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry dsf 555/tcp
Prevalence
nmap-services open-frequency 555/tcp ≈ 0.000238 (~0.024%); 555/udp ≈ 0.000329 (~0.033%) [Confirmed] — this site's own tooling
Related ports
no specific cluster identified; see the /port/ hub [Unknown]

Primary use

no documented protocol semantics beyond the registered name; no RFC or vendor spec found

[Confirmed/Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=555

Other/unofficial uses

reported historical use by 1998–99-era Windows backdoor/RAT trojans (Phase Zero, Ini-Killer, Net Administrator, Stealth Spy)

[Likely] — http://www.textfiles.com/uploads/trojanports.txt, https://seclists.org/ids/1999/Aug/16

Security implications

no CVE tied to the port as of an August 2026 NVD search; legacy trojan-list association only

[Likely] — https://seclists.org/ids/1999/Aug/16, http://www.textfiles.com/uploads/trojanports.txt

Typically seen on

legacy Windows 9x/ME hosts historically; otherwise an anomaly [Likely]

Analyst note
An open 555/tcp carries no legitimate documented service and has a legacy trojan association — investigate rather than assume benign use.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dsf UDP — 0.03%
dsf TCP — 0.02%
IANA name
dsf
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.