Port 3127MyDoom Backdoor

TCP 3127 is known as a legacy MyDoom backdoor; IANA separately assigns the port as CTX Bridge Port.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
7/10

risk

lookups
0

rank 993 of 4,497 · top 22%

also known as ctx-bridge, CTX Bridge Port

Technical Details

what runs on :3127

IANA assigns TCP and UDP 3127 the name ctx-bridge and the description “CTX Bridge Port,” but that entry does not establish a public protocol with a defined handshake or framing. The port is also known historically for the MyDoom worm’s TCP backdoor listener, which used a malware-specific protocol rather than a standard service protocol. Do not infer that an ordinary CTX Bridge service is present just because this port is open.

Security Information

exposure of :3127

risk score

7/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

security averages 3.1 across 350 ports — this one sits 3.9 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

The historical MyDoom listener provided a remote-access path to an infected host; it is not a service that should be exposed to the internet. If TCP 3127 is unexpectedly open, identify the listening process and investigate the host for compromise rather than assuming it is the IANA-registered service. The malware use is legacy, and the available scan data does not show this port open.

the 8 most looked-up other ports in security — 350 ports carry that label.

risk mix of the 8 listed

  • caution100%

2 of 8 encrypted