Network port detail · UDP/TCP

146

Iso-tp0
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Low-volume, sporadic opportunistic scan traffic per SANS ISC (accessed 2026-07-10), consistent with generic mass port-sweep noise. A dated third-party port list cross-references an 'Infector' trojan on this port; that association is not independently confirmed and is treated as low-confidence historical trivia, not a current threat indicator.
// analyst note
An open port 146 today is unlikely to reflect a legitimate, actively used service given the port's obsolete OSI/X.25 origin; treat responsiveness as an anomaly worth investigating rather than a normal finding.
[ 01 ] — Context

About port 146/tcp.

Updated  ·  Confidence: Medium

Port 146 is registered with IANA as iso-tp0, described as "ISO-IP0," with a blank Reference field and dual registration on both 146/tcp and 146/udp (identical service name and description on both rows). The historical protocol context traces to RFC 1086, "ISO-TP0 bridge between TCP and X.25" (May 1988), which describes a bridge technique for interconnecting ISO Transport Protocol Class 0 (TP0) traffic between a TCP/IP internet and an X.25 subnetwork: a TP0-over-TCP host opens a TCP connection to a bridge process on this port and signals the desired X.25 destination address, and the bridge relays traffic onward over X.25. IANA does not list RFC 1086 (or any RFC) in the Reference column for this entry, so that association is reported as historical context rather than IANA's formal citation. This is a 1980s-era OSI/X.25 interconnection mechanism that predates the dominance of TCP/IP; no current mainstream client or server software is known to use port 146 for its registered purpose, and it should be treated as effectively dormant. Passive internet scan telemetry shows only low-volume, sporadic background noise consistent with routine mass port sweeps rather than targeted activity, and a single dated third-party port list ties port 146 to an "Infector" trojan — a low-confidence historical data point, not a confirmed current threat.

IANA assignment
iso-tp0 — "ISO-IP0"; Reference field blank in the registry; dual-registered 146/tcp + 146/udp with identical name/description [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Range class
well-known (0–1023)
Prevalence
nmap-services observed open-frequency 146/tcp ≈ 0.000577 (very low — roughly 6 in 10,000 scanned hosts in the nmap-services sample) [Confirmed] — nmap-services dataset; the dual-registered 146/udp side is somewhat higher at ≈ 0.000890 [Confirmed] — nmap-services dataset
Related ports
Unknown — not established in this research pass

Primary use

historic ISO-TP0-over-TCP-to-X.25 bridge mechanism; client opens a TCP connection to port 146 and signals an X.25 address, per RFC 1086 (May 1988) — not cited by IANA as this port's formal reference, so treated as historical context

[Likely] — https://datatracker.ietf.org/doc/html/rfc1086, https://www.rfc-editor.org/rfc/rfc1086

Other/unofficial uses

none well-documented; no known current mainstream software uses this port [Unknown]

Security implications

SANS ISC port-146 dashboard (accessed 2026-07-10) shows low-volume, sporadic opportunistic scan traffic consistent with generic internet background noise; the same page cross-references a dated "Infector" trojan port-list entry, which is not independently confirmed by IANA or a primary advisory and should be treated as low-confidence trivia rather than an active threat indicator

[Likely] — https://isc.sans.edu/data/port/146

Typically seen on

legacy OSI/X.25 interconnection gateways (historical); otherwise generic scan noise rather than a deployed service [Likely]

Analyst note
An open port 146 today is unlikely to reflect a legitimate, actively used service given the port's obsolete OSI/X.25 origin; treat responsiveness as an anomaly worth investigating rather than a normal finding.
[ 02 ] — Context

About port 146/udp.

Updated  ·  Confidence: Medium

Port 146/udp is registered with IANA under the service name iso-tp0, described simply as "ISO-IP0," with a matching dual registration on 146/tcp carrying the identical name and description — both rows are otherwise blank in the registry (no assignee, no contact, no registration or modification date, and no RFC reference). The name points to ISO Transport Protocol Class 0 (TP0), one of the connection-oriented transport classes from the OSI transport-layer stack, and the closest documented tie is RFC 1086 (December 1988), which specifies a mechanism for running ISO TP0 tunneled over a TCP connection so that OSI-speaking hosts could interoperate across X.25 and TCP/IP networks during the early internetworking era when OSI and TCP/IP protocol suites were expected to coexist. RFC 1086 describes only the TCP bridge, however — no distinct specification was found defining an ISO-TP0 service running natively over UDP, so the udp/146 entry reads as the registry's conventional TCP/UDP pairing rather than an independently specified UDP protocol. No actively maintained software was found binding to this port today; ISO TP0/X.25 bridging is essentially extinct 1990s-era OSI-migration tooling. Present-day exposure appears to be ordinary internet background scanning rather than a targeted service or campaign.

IANA assignment
iso-tp0 — "ISO-IP0"; reference blank; assignee/contact/dates blank; dual-registered 146/tcp + 146/udp with identical name/description [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-370; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed] — port number falls in the IANA well-known range
Prevalence
nmap-services observed open-frequency 146/udp ≈ 0.00089 — very low (roughly 9 in 10,000 scanned hosts in the nmap-services sample); the paired 146/tcp row is lower still at ≈ 0.000577 [Confirmed] — nmap-services dataset
Related ports
146/tcp (identical dual registration, same name and description)

Primary use

ISO Transport Protocol Class 0 tunneled over TCP for OSI/X.25 interoperability

[Confirmed] — https://datatracker.ietf.org/doc/html/rfc1086

Other/unofficial uses

none identified in current research [Unknown]

Security implications

SANS ISC's port-146 activity page carries a crowd-sourced "Infector [trojan]" label alongside iso-tp0 for both tcp and udp; this is an unverified legacy port-list heuristic, not a confirmed active malware family. Observed scanning was low-volume generic background noise (top source logged 14 hits "today" / 59 "yesterday" as of the 2026-07-10 fetch)

[Likely] — https://isc.sans.edu/data/port/146

Typically seen on

legacy/obsolete OSI-over-IP interoperability contexts historically; no modern software identified [Unknown]

UDP variant
no distinct specification found defining ISO-TP0 over UDP; RFC 1086 covers only the TCP bridge, so udp/146 is likely the registry's conventional paired assignment rather than an independently defined service [Likely] — https://datatracker.ietf.org/doc/html/rfc1086
Analyst note
essentially dormant; an open 146/udp is unlikely to be a legitimate modern service and any observed traffic is most plausibly routine internet scanning rather than the historical ISO-TP0 use.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
iso-tp0 UDP 0.09%
iso-tp0 TCP ISO-IP0 0.06%
IANA name
iso-tp0
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.