666
Summary
- // if you see it open
- Not a standard service on modern hosts. Because '666' is culturally loaded it has been reused by trojans/backdoors historically (threat-reported); a hit on 666 is often unrelated to Doom (e.g. spoofed Windows Messenger spam). An open 666 warrants identifying the listening process.
- // analyst note
- An open 666 today is unusual — most likely a custom/game app or a misconfiguration — but the number's malware history means it warrants a quick triage to identify the listening process.
About port 666.
Port 666/tcp is registered with IANA as doom with the description "doom Id Software," an assignee and contact of [ddt], no registration or modification dates, and a blank reference field — verified directly against the live registry this pass (registry Last Updated 2026-05-29), on both 666/tcp and 666/udp; the older service name mdqs is also still listed for 666/tcp and 666/udp with empty fields. It is the network port associated with id Software's Doom (1993), the pioneering first-person shooter, used for multiplayer gameplay. A historical nuance worth noting is that classic 1993 Doom multiplayer ran over IPX rather than IP, so the IANA entry registers the port number for id Software's networked games rather than implying that classic Doom used TCP/UDP 666 over the internet; several modern source ports use other ports. The IANA reference field is blank. Security-wise the substantive point is de-facto and threat-reported rather than part of the IANA assignment: because "666" is a culturally loaded number, it has been reused over the years by various trojans and backdoors — names reported in port-list references include Attack FTP, Back Construction, Doom Trojan, and Satanz Backdoor — but these should be treated as community/threat-reported associations, not IANA-sanctioned, and a hit on 666 is often unrelated to Doom (for example spoofed Windows Messenger spam). For an analyst, an open 666 today is unusual — most likely a custom or game application or a misconfiguration — but the number's malware history means it warrants a quick triage to identify the listening process, since it is not a standard service on modern hosts.
- IANA assignment
doom— "doom Id Software"; reference (blank — no RFC cited in IANA registry); assignee/contact [ddt]; no registration/modification dates; legacymdqsalso still listed; dual-registered 666/tcp + 666/udp[IANA-assigned, verified live] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- low; nmap-services de-facto low (qualitative this batch) [Well-established] — nmap-services file
- Related ports
- general game-server ports; legacy
mdqs(same port)
Primary use
networking port for id Software's Doom (1993) multiplayer
Other/unofficial uses
de-facto reuse by trojans/backdoors (Attack FTP, Back Construction, Doom Trojan, Satanz Backdoor)
Security implications
not a standard modern service; the "666" novelty has drawn historical malware reuse (threat-reported); an open 666 warrants identifying the listening process [Community/de-facto/Threat-reported]
Typically seen on
game servers, legacy/custom apps, or (historically) backdoors
- Analyst note
- An open 666 today is unusual — most likely a custom/game app or a misconfiguration — but the number's malware history means it warrants a quick triage to identify the listening process.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| doom | UDP | doom Id Software | 0.10% |
| doom | TCP | mdqs | 0.03% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.