176
Summary
- // if you see it open
- No CVEs, malware associations, or notable internet-scanning commentary specific to this port were found; it does not appear on commonly-referenced top-scanned or top-exploited port lists. Absence of findings is not a confirmed clean bill.
- // analyst note
- an open 176/tcp is extremely rare and effectively undocumented outside the bare IANA registration — treat as an anomaly warranting investigation rather than an expected service.
About port 176/tcp.
Port 176/tcp is registered with IANA under the service name genrad-mux, described simply as "GENRAD-MUX," with both the assignee and contact fields listing Ron Thornton and no RFC or other reference cited. The registry entry is dual-registered — 176/udp carries an identical service name, description, assignee, and contact — but IANA's registry provides no protocol specification, registration date, or modification date for either row, and no service code is recorded. The name strongly suggests an association with GenRad, Inc. (formerly General Radio Company), a long-running manufacturer of electronic test, measurement, and automated test equipment; "MUX" in the service name implies some kind of multiplexed control or data channel for that equipment, but IANA does not publish any technical detail beyond the bare name, and no vendor documentation, RFC, or protocol write-up describing an actual "GENRAD-MUX" wire protocol was found in this pass. No malware, CVE, or notable internet-scanning association turns up for this port, and it does not appear on commonly-referenced top-scanned or top-exploited port lists; port-lookup aggregator sites (SpeedGuide, T1 Shopper, GRC) only mirror IANA's bare name entry with no added detail of their own. Practically, an analyst encountering 176/tcp open on a host should treat it as either a legacy or niche GenRad test-equipment interface or, more plausibly given its extreme rarity and total lack of documented deployment, an unrelated, misconfigured, or attacker-controlled listener worth further investigation.
- IANA assignment
genrad-mux— "GENRAD-MUX"; reference (blank — no RFC cited in IANA registry); assignee/contact Ron Thornton; dual-registered 176/tcp + 176/udp with identical fields [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services observed open-frequency 176/tcp ≈ 0.000025 (very low — roughly 2 to 3 in 100,000 scanned hosts in the nmap-services sample); the dual-registered 176/udp side is higher at ≈ 0.000313 [Confirmed] — nmap-services dataset. The figure records scan-observed openness on the port number, not confirmed GENRAD-MUX use, and at that magnitude it corroborates the extreme-rarity reading [Confirmed]
- Related ports
- none specifically documented; no clear cluster association found
Primary use
no published protocol specification; name suggests a GenRad, Inc. (formerly General Radio Company) test/measurement equipment multiplexed channel, but this is an inference, not an IANA-confirmed function [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml; https://www.speedguide.net/port.php?port=176
Other/unofficial uses
none documented [Unknown]
Security implications
no CVEs, malware associations, or notable scanning commentary specific to this port found; not on commonly-referenced top-scanned/top-exploited port lists [Unknown — absence of findings, not a confirmed clean bill] — searched via WebSearch/WebFetch, no results
Typically seen on
possible legacy/niche GenRad test-equipment interface (inferred, undocumented); otherwise an anomaly given no widescale legitimate deployment is documented [Unknown]
- Analyst note
- an open 176/tcp is extremely rare and effectively undocumented outside the bare IANA registration — treat as an anomaly warranting investigation rather than an expected service.
About port 176/udp.
Port 176/udp is registered with IANA under the service name genrad-mux, description "GENRAD-MUX," with contact/assignee listed as Ron Thornton. This is a dual registration: 176/tcp carries the identical service name, description, and assignee, and the IANA registry's reference field is blank for both entries — no RFC or standards document is cited that specifies what the GENRAD-MUX protocol actually does on the wire. The name plausibly nods to GenRad Inc. (the electronic test-and-measurement equipment maker historically known as General Radio), with "MUX" suggesting some multiplexed control or test-instrument channel, but this is an unverified naming inference rather than a sourced fact, and it is recorded here as Unknown. No mainstream, currently maintained software, daemon, or product was found documented as actively binding a live network service to TCP or UDP port 176 in this research pass. GRC's Port Authority database lists port 176 with only the bare name and purpose and no documented malware, trojan, or CVE associations; a secondary aggregator (auditmypc.com) reports no known virus/trojan for UDP 176 but is a low-authority site whose own disclaimer states accuracy is not guaranteed, so that claim is not treated as authoritative here. Port 176 falls in the well-known range (0–1023). Given the combination of a formally registered name with no protocol specification, no confirmed active software, and no security-advisory history, an open 176/udp on a live host should be treated as an anomalous, low-prevalence finding worth investigating as custom or internal traffic, a decoy, or a misconfiguration rather than assumed to be a standard, currently used multiplexing service.
- IANA assignment
genrad-mux— "GENRAD-MUX"; reference (blank — no RFC cited in IANA registry); assignee/contact Ron Thornton; dual-registered 176/tcp + 176/udp (identical rows) [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=4)- Range class
- well-known (0–1023) [Confirmed] — IANA registry
- Prevalence
- nmap-services observed open-frequency 176/udp ≈ 0.000313 — very low (roughly 3 in 10,000 scanned hosts in the nmap-services sample); the paired 176/tcp row is rarer still at ≈ 0.000025 [Confirmed] — nmap-services dataset
- Related ports
- none confirmed in this pass; no cross-referenced adjacent registry entries located [Unknown]
Primary use
protocol function not documented in any RFC or spec located; name may allude to GenRad Inc. test/measurement equipment with a multiplexed channel, but this is an unverified naming inference, not a sourced fact [Unknown]
Other/unofficial uses
none documented; no mainstream software found binding a live service to TCP/UDP 176 [Unknown]
Security implications
GRC Port Authority lists only the bare name/purpose, with no trojan, malware, or CVE associations documented; auditmypc.com (low-authority, self-disclaimed accuracy) reports "No" known virus/trojan for UDP 176 but is not treated as authoritative
Typically seen on
no confirmed active software; an open 176/udp is statistically anomalous and worth investigating as custom/internal traffic, a decoy, or a misconfiguration
- Analyst note
- a registered name with no protocol spec, no confirmed software, and no security-advisory history — treat a responsive 176/udp as anomalous rather than a normal, expected service [Likely]
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| genrad-mux | UDP | — | 0.03% |
| genrad-mux | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.