Network port detail · UDP/TCP

166

S-net
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Unknown — no CVEs, named malware, or botnet C2 association found for 166/tcp or 166/udp; appears to be a dormant legacy registration with negligible real-world footprint.
// analyst note
An open 166/tcp has no recognized modern service mapping; treat as anomalous and investigate rather than assume a known protocol.
[ 01 ] — Context

About port 166/tcp.

Updated  ·  Confidence: Medium

Port 166/tcp is registered with IANA under the service name s-net, described only as "Sirius Systems," with both assignee and contact listed as [Brian_Lloyd]. The registration is dual — 166/udp carries an identical entry (same service name, description, assignee, and contact) — but IANA's Registration Date, Modification Date, and Reference (RFC) columns are all blank for this row, consistent with many early Internet-era assignments that predate the registry's later record-keeping conventions; no date or RFC is invented here to fill that gap. Brian Lloyd was an active IETF/RFC-era contributor in the late 1980s and early 1990s, credited on several early routing- and PPP-related RFCs, which situates this assignment loosely in that period, though IANA itself records no exact date. Beyond the bare IANA name and description, no protocol specification, vendor documentation, or product literature describing a "Sirius Systems" product or an "s-net" protocol could be located — the service name does not correspond to any known modern product, open-source implementation, or widely deployed software. There is likewise no evidence of CVEs, named malware, botnet command-and-control usage, or exposure-scanning writeups (Shodan, nmap-services frequency data, or similar) specifically tied to port 166 on either transport. The most defensible characterization is a legacy, likely-dormant IANA registration with no confirmed modern implementation and negligible real-world footprint; an analyst encountering traffic on 166/tcp should treat it as anomalous rather than expect a recognized service, and should not assume it maps to any documented protocol beyond the registry's placeholder name and description.

IANA assignment
s-net — "Sirius Systems"; reference (blank — no RFC cited in IANA registry); assignee/contact [Brian_Lloyd]; dual-registered 166/tcp + 166/udp with identical metadata [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Registration/modification dates
blank in the IANA registry CSV for this entry — reported as blank rather than fabricated [Confirmed] — IANA registry CSV
Prevalence / security implications
Unknown — no CVEs, named malware/trojan association, or exposure-scanning (Shodan/nmap) writeups found specifically citing 166/tcp; appears to be a low- or no-footprint port in current scanning data [Unknown]
Related ports
none confirmed via registry or research [Unknown]

Primary use

Unknown beyond the bare IANA name/description; no protocol specification or vendor documentation found for "s-net" / "Sirius Systems"

[Unknown] — IANA Service Names and Port Numbers registry

Other/unofficial uses

Unknown — no software or product found that implements this service today [Unknown]

Typically seen on

Unknown — no confirmed modern deployments located; best characterized as a legacy/dormant registration [Unknown]

Analyst note
An open 166/tcp has no recognized modern service mapping; treat as anomalous and investigate rather than assume a known protocol.
[ 02 ] — Context

About port 166/udp.

Updated  ·  Confidence: Medium

Port 166/udp is registered with IANA under the service name s-net, described simply as "Sirius Systems," with both the assignee and contact fields listing [Brian_Lloyd]. The registration is dual — an identical entry exists for 166/tcp, same service name, same description, same contact — meaning the assignment covers both transports equally rather than being UDP-specific. The registry's Registration Date, Modification Date, Reference, Service Code, and Unauthorized Use Reported fields are all blank; there is nothing more to report there beyond confirming they are empty in the source. The s-net name also surfaces in RFC 1340 ("Assigned Numbers," Reynolds & Postel, July 1992), a now-obsolete Assigned Numbers RFC that predates the modern online IANA registry — a legitimate historical citation, though it is not what the current IANA Reference column points to (that column is empty). No independent protocol specification, current software, or vendor documentation describing what "Sirius Systems" s-net actually does was located; the registration reads as a legacy, effectively dormant IANA assignment from the early days of the ports registry rather than something in active mainstream use today. On the security side, several third-party, non-vendor compiled port lists associate TCP port 166 with the "NokNok" backdoor/trojan, an older Windows 95/98/ME/2000-era remote-access tool with password-stealing and IRC-bot behavior; no primary antivirus-vendor writeup pinning NokNok specifically to this port was found, so that association is treated as Likely rather than Confirmed, and it is documented mostly against the TCP side rather than UDP specifically. Live SANS Internet Storm Center scan-activity data for port 166 shows only low, scattered background-noise-level probing, consistent with routine internet-wide scanning rather than any targeted or currently elevated threat, and no CVEs specific to this port were found.

IANA assignment
s-net — "Sirius Systems"; assignee/contact [Brian_Lloyd]; Registration Date/Modification Date/Reference/Service Code/Unauthorized Use Reported all blank; dual-registered 166/tcp + 166/udp (identical row) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Range class
well-known (0–1023) [Confirmed]

Primary use today

Unknown / effectively dormant — no independent technical specification, current software, or vendor documentation for the Sirius Systems s-net protocol was located

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt

Common software

none identified [Unknown]

Security implications

multiple third-party (non-vendor) compiled port lists associate TCP port 166 with the "NokNok" backdoor/trojan (Windows 95/98/ME/2000 era; password-stealing, IRC-bot behavior); no primary AV-vendor writeup confirms the pairing, and it is documented against TCP rather than UDP specifically [Likely] — https://www.auditmypc.com/tcp-port-166.asp, https://github.com/d4t4king/dk-mods/blob/master/enhanced-fw-mod/var/smoothwall/mods/enhanced-fw-logs/etc/portlist_suspect_use

Historical documentation
s-net also appears in RFC 1340 ("Assigned Numbers," July 1992), an obsolete Assigned Numbers RFC predating the current online registry; distinct from the modern IANA Reference field, which is blank [Confirmed] — https://www.ietf.org/rfc/rfc1340.txt
Live scan activity
SANS ISC port-166 data (checked 2026-07-10) shows only low, scattered background-scan volume, no elevated or targeted activity, and no CVEs specific to this port [Confirmed] — https://isc.sans.edu/data/port/166
Related port
166/tcp — identical dual-registered s-net counterpart [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
s-net UDP Sirius Systems 0.05%
s-net TCP Sirius Systems 0.00%
IANA name
s-net
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.