@Roberto Romeo Apologies for the delay in response and all the inconvenience caused because of the issue.
Firstly I would suggest you to migrate your classic deployment to ARM. Reason being classic deployment will soon be expired and there are no new feature or capabilities which you can take advantage of as such in classic deployment. For migration and other information you can refer to this.
Now coming to your question Classic VM in Azure do make use of some hidden open ports for internal communication management between cloud controller and VM. Also 445 can be used for SMB over internet and can also be used for event collection and that can be the reason the mentioned port are open.
Hope it helps!!!
Please "Accept as Answer" if it helped so it can help others in community looking for help on similar topics.