Network port detail · UDP/TCP

666

Doom
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Not a standard service on modern hosts. Because '666' is culturally loaded it has been reused by trojans/backdoors historically (threat-reported); a hit on 666 is often unrelated to Doom (e.g. spoofed Windows Messenger spam). An open 666 warrants identifying the listening process.
// analyst note
An open 666 today is unusual — most likely a custom/game app or a misconfiguration — but the number's malware history means it warrants a quick triage to identify the listening process.
[ 01 ] — Context

About port 666.

Updated  ·  Confidence: High

Port 666/tcp is registered with IANA as doom with the description "doom Id Software," an assignee and contact of [ddt], no registration or modification dates, and a blank reference field — verified directly against the live registry this pass (registry Last Updated 2026-05-29), on both 666/tcp and 666/udp; the older service name mdqs is also still listed for 666/tcp and 666/udp with empty fields. It is the network port associated with id Software's Doom (1993), the pioneering first-person shooter, used for multiplayer gameplay. A historical nuance worth noting is that classic 1993 Doom multiplayer ran over IPX rather than IP, so the IANA entry registers the port number for id Software's networked games rather than implying that classic Doom used TCP/UDP 666 over the internet; several modern source ports use other ports. The IANA reference field is blank. Security-wise the substantive point is de-facto and threat-reported rather than part of the IANA assignment: because "666" is a culturally loaded number, it has been reused over the years by various trojans and backdoors — names reported in port-list references include Attack FTP, Back Construction, Doom Trojan, and Satanz Backdoor — but these should be treated as community/threat-reported associations, not IANA-sanctioned, and a hit on 666 is often unrelated to Doom (for example spoofed Windows Messenger spam). For an analyst, an open 666 today is unusual — most likely a custom or game application or a misconfiguration — but the number's malware history means it warrants a quick triage to identify the listening process, since it is not a standard service on modern hosts.

IANA assignment
doom — "doom Id Software"; reference (blank — no RFC cited in IANA registry); assignee/contact [ddt]; no registration/modification dates; legacy mdqs also still listed; dual-registered 666/tcp + 666/udp
[IANA-assigned, verified live] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
low; nmap-services de-facto low (qualitative this batch) [Well-established] — nmap-services file
Related ports
general game-server ports; legacy mdqs (same port)

Primary use

networking port for id Software's Doom (1993) multiplayer

[Well-established] — IANA registry

Other/unofficial uses

de-facto reuse by trojans/backdoors (Attack FTP, Back Construction, Doom Trojan, Satanz Backdoor)

[Community/de-facto/Threat-reported] — port-list references

Security implications

not a standard modern service; the "666" novelty has drawn historical malware reuse (threat-reported); an open 666 warrants identifying the listening process [Community/de-facto/Threat-reported]

Typically seen on

game servers, legacy/custom apps, or (historically) backdoors

Analyst note
An open 666 today is unusual — most likely a custom/game app or a misconfiguration — but the number's malware history means it warrants a quick triage to identify the listening process.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
doom UDP doom Id Software 0.10%
doom TCP mdqs 0.03%
IANA name
doom
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.