Network port detail · UDP/TCP

116

Ansanotify
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No authoritative source found associating port 116/tcp with a specific CVE, malware family, or active internet-scanning campaign. Only unsourced generic port-database boilerplate exists, which is not treated as verified.
// analyst note
Name preserves a 1980s–1990s distributed-systems research architecture; not a recognized modern service. Treat an open 116 as an anomaly, not a known good service.
[ 01 ] — Context

About port 116/tcp.

Updated  ·  Confidence: Medium

Port 116/tcp is registered with IANA as ansanotify with the description "ANSA REX Notify," assignee and contact Nicola J. Howarth, and a blank reference field; the entry is dual-registered identically on TCP and UDP. The name traces to ANSA (Advanced Network Systems Architecture), a distributed-systems and software-bus middleware research architecture developed by Architecture Projects Management Ltd of Cambridge, UK, active roughly from the mid-1980s through the 1990s. Within that architecture, REX was the remote-execution facility and ansanotify appears to be the associated notification/event service that the port name preserves. There is no RFC or reference document listed in the IANA registry for this entry, and no registration or modification date is exposed in the registry rows, so those fields remain blank rather than invented. In practical terms this is an obsolete legacy research-middleware assignment: no evidence was found of actively maintained software using port 116 in current deployments, and no authoritative source ties the port to a specific CVE, malware family, or ongoing internet-scanning campaign — only generic, unsourced port-database boilerplate exists, which is not treated here as verified. For an analyst, a responsive port 116 is therefore best treated as an anomaly worth investigating rather than a recognized modern service; the historical ANSA background explains the name but not any live traffic you are likely to encounter today.

IANA assignment
ansanotify — "ANSA REX Notify"; reference (blank — no RFC cited in IANA registry); assignee and contact Nicola J. Howarth; dual-registered 116/tcp + 116/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (cached copy, lines 301–302; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
Range class
well-known (0–1023) [Confirmed]
IANA reference/RFC
none listed (blank in registry — not fabricated) [Confirmed] — IANA registry
Registration/modification date
Unknown (blank in registry; no date exposed for this entry — not fabricated) [Unknown]
Prevalence
nmap-services observed open-frequency 116/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 116/udp ≈ 0.000445, some thirty-four times higher. Both negligible; consistent with a dormant legacy assignment
Related ports
ansatrader (124), ansaphone — other ANSA-named legacy assignments in the registry

Primary use

notification/event service of the ANSA REX distributed-systems middleware; name-only assignment, no protocol spec in the registry

[Likely] — IANA registry description "ANSA REX Notify"

Protocol background

ANSA (Advanced Network Systems Architecture) was a distributed-systems / software-bus research architecture from Architecture Projects Management Ltd, Cambridge, UK (mid-1980s–1990s); REX was its remote-execution facility

[Likely] — FOLDOC (https://foldoc.org/Advanced+Network+Systems+Architecture)

Security implications

Unknown — no authoritative source found associating 116/tcp with a CVE, malware family, or active scanning campaign; only unsourced generic port-database text exists (not treated as verified) [Unknown]

Typically seen on

Unknown; a responsive port 116 today is best treated as an anomaly worth investigating

Current usage (2026)
Unknown / likely obsolete legacy research middleware; no evidence of actively maintained software using this port in current deployments [Unknown]
Analyst note
Name preserves a 1980s–1990s distributed-systems research architecture; not a recognized modern service. Treat an open 116 as an anomaly, not a known good service.
[ 02 ] — Context

About port 116/udp.

Updated  ·  Confidence: Medium

Port 116/udp is registered with IANA as ansanotify with the description "ANSA REX Notify," assignee Nicola J. Howarth, and a blank reference field. It is dual-registered on both transports: 116/tcp carries the identical service name, description, and assignee, so the UDP entry is one half of a matched TCP/UDP pair rather than a standalone assignment. The name traces to ANSA — the Advanced Network Systems Architecture project run by APM Ltd. in Cambridge, UK, an early-1990s distributed-computing research programme whose ANSAware toolkit was a precursor to CORBA-style middleware. "REX" was ANSA's Remote EXecution invocation protocol, and the "Notify" component was its event/notification service; 116 was the port reserved for that notifier. In practice this is a historical assignment with negligible modern deployment: no reference RFC is cited in the IANA registry, no current mainstream software or daemon is documented as using the port, and targeted searches (July 2026) surfaced no CVE entries, no Shodan/Censys exposure statistics, and no sourced malware or trojan campaigns tied to 116/udp. Some legacy port-database sites list port 116 in generic "trojan port" tables, but they themselves state no virus or trojan is confirmed to use it — that is a boilerplate list artifact, not a documented incident, and it is treated here as Unknown rather than a security finding. For an analyst, a responsive 116/udp is an anomaly worth investigating rather than an expected service, since legitimate ANSAware use effectively disappeared decades ago.

IANA assignment
ansanotify — "ANSA REX Notify"; reference (blank — no RFC cited in IANA registry); assignee Nicola J. Howarth [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (cached CSV line 302); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Dual registration
116/tcp is registered identically (ansanotify / "ANSA REX Notify", same assignee) — this UDP entry is half of a matched TCP/UDP pair [Confirmed] — cached IANA CSV line 301
Range class
system / well-known (0–1023) [Confirmed] — port number 116 falls in the well-known range
Registration / modification date
null — not displayed in the IANA registry for this assignment; not fabricated [Confirmed as blank] — cached IANA CSV line 302 (columns 7–12 empty)
Related ports
116/tcp (same assignment); ANSA-era distributed-computing services

Primary use

notification/event component ("REX Notify") of the ANSA / ANSAware distributed-computing platform (APM Ltd., Cambridge UK; early-1990s CORBA-precursor middleware)

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Common software

Unknown — no current mainstream software documented; historically tied to ANSAware tooling, no modern (2020s) implementations found [Unknown]

Security implications / exposure

Unknown — no CVE entries, no Shodan/Censys exposure stats, no sourced malware/trojan campaigns found; generic legacy "trojan port" list mentions are unsourced boilerplate, not incidents

[Unknown] — https://www.auditmypc.com/udp-port-116.asp

Typically seen on

no expected modern host class; a responsive 116/udp is an anomaly worth investigating

Analyst note
Legacy assignment with negligible live use. Treat an open 116/udp as an anomaly (decoy, custom app, or backdoor) rather than a normal service; do not repeat unsourced "trojan port" folklore as fact.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ansanotify UDP ANSA REX Notify 0.04%
ansanotify TCP ANSA REX Notify 0.00%
IANA name
ansanotify
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.