UDP Port 135 – epmap
About UDP Port 135
Port 135 is registered with the Internet Assigned Numbers Authority (IANA) for epmap. The IANA description reads: ‘DCE endpoint resolution’. This port appears in 8 IDS rules and does not have notable malware activity indicators in our data.
IDS Rule References
8 IDS / security rules reference UDP port 135. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 2): attempted-admin (6), protocol-command-decode (2).
Sample rule descriptions for UDP port 135:
- OS-WINDOWS DCERPC Messenger Service buffer overflow attempt
- OS-WINDOWS DCERPC NCADG-IP-UDP lsass DsRolerUpgradeDownlevelServer overflow attempt
- OS-WINDOWS DCERPC NCADG-IP-UDP ISystemActivator CoGetInstanceFromFile attempt
- OS-WINDOWS DCERPC NCADG-IP-UDP msqueue function 4 overflow attempt
- OS-WINDOWS Messenger message little endian overflow attempt
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).
