171
Summary
- // if you see it open
- No confirmed current use, legitimate or malicious. A low-authority aggregator (AuditMyPC) generically flags 171/tcp as historically Trojan-associated with no named malware family or dated incident; the more authoritative Gary Kessler bad-ports reference does not list port 171 at all. Treat the Trojan flag as unverified rather than confirmed.
- // analyst note
- essentially dormant port; no confirmed legitimate or malicious current use — treat any observed traffic as anomalous and worth investigating on its own merits, not on the basis of the unverified Trojan flag.
About port 171/tcp.
Port 171/tcp is registered with IANA under the service name multiplex, described only as "Network Innovations Multiplex." The registry entry is sparse: no assignee, no contact, no registration or modification date, and no RFC or reference are recorded, and this is not a gap in research — the IANA Service Name and Transport Protocol Port Number Registry itself carries the entry with those columns blank. Port 171/udp shares the identical service name and description as a dual registration, likewise with every other column empty. No vendor documentation, protocol specification, or product page describing "Network Innovations" or its multiplexing scheme could be located, so the underlying protocol behavior is effectively unknown beyond the bare name-to-number reservation. Empirically, the port is almost never seen in the wild: nmap's service-frequency data — built from large real-world scan corpora — records 171/tcp at a frequency of 0.000000 (statistically unobserved) and 171/udp at a low 0.000412. Some low-authority "bad ports" aggregator pages generically flag 171/tcp as historically Trojan-associated, but name no specific malware family or dated incident, and the well-regarded Gary Kessler bad-ports reference does not list port 171 at all, so that claim is recorded here as unverified rather than fact. Net assessment: an obscure, dormant legacy registry entry with negligible real-world footprint and no confirmed current use, malicious or otherwise.
- IANA assignment
multiplex— "Network Innovations Multiplex"; assignee/contact/reference/dates all blank in the registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry- Dual registration
- 171/udp shares the identical service name and description, all other columns blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Range class
- well-known (0–1023) [Confirmed]
- IANA reference/RFC
- none listed; left blank rather than invented [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Registration date
- not published for this entry (contrast with neighboring registrations that do carry contact/date data) [Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Prevalence
- nmap-services open-frequency 171/tcp ≈ 0.000000 (unobserved), 171/udp ≈ 0.000412 [Confirmed] — https://svn.nmap.org/nmap/nmap-services
Primary use
legacy vendor-registered name ("Network Innovations Multiplex") with no accompanying protocol spec found
Common software
none identified currently binding this port under this name [Unknown]
Malware association
unverified — a low-authority aggregator generically flags 171/tcp as historically Trojan-linked with no named family or date; the Gary Kessler bad-ports reference does not list this port at all
- Analyst note
- essentially dormant port; no confirmed legitimate or malicious current use — treat any observed traffic as anomalous and worth investigating on its own merits, not on the basis of the unverified Trojan flag.
About port 171/udp.
Port 171/udp is registered with IANA under the service name multiplex, described simply as "Network Innovations Multiplex." The registration is dual — 171/tcp carries the identical service name and description — but almost every other field in the IANA registry entry (assignee, contact, registration date, modification date, and reference/RFC) is blank. No RFC or other IANA reference document was ever published to define the protocol, which means there is no authoritative specification of how the service actually behaves on the wire; "multiplex" appears to be a legacy, vendor-specific name reserved in IANA's early port-numbering era rather than a protocol that was ever standardized or widely documented. A live fetch of the current IANA Service Name and Transport Protocol Port Number Registry page confirms the same service name and description are still listed today, so the assignment has persisted unchanged for decades without accruing any further documentation. No software, vendor product, malware family, or notable scanning/exposure research tied specifically to port 171/udp was located in this research pass, and it does not appear on common threat-intelligence port watchlists. Given the total absence of an RFC, a working implementation, or reported real-world traffic, this entry should be treated as a dormant, essentially unused legacy IANA registration rather than an active service an analyst is likely to encounter.
- IANA assignment
multiplex— "Network Innovations Multiplex"; reference blank; assignee blank; contact blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, corroborated live at https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=171- Dual registration
- 171/tcp carries the identical service name and description, also with all other columns blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Range class
- well-known (0–1023) [Confirmed] — port number itself
- Registration/modification dates
- blank in the IANA registry for both 171/tcp and 171/udp; no date fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Related ports
- 171/tcp (same service name, dual registration) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
legacy proprietary multiplexing service reserved for a vendor ("Network Innovations") in IANA's early port-registration era; never standardized in an RFC
Common software/vendor implementation
Unknown — no current or historical software, client, or server documented as using this port was found [Unknown]
Security implications / exposure history
no documented scanning campaigns, malware/C2 use, or CVEs specific to 171/udp found; port does not appear on common malicious-port watchlists; treated as dormant/legacy rather than actively risky, but this is an absence-of-evidence finding, not a confirmed-safe finding
Typically seen on
Unknown — no documented deployment base [Unknown]
- Reference/RFC
- none published; IANA Reference column is blank, so no RFC is cited [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, live IANA registry search
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| multiplex | UDP | Network Innovations Multiplex | 0.04% |
| multiplex | TCP | Network Innovations Multiplex | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.