182
Summary
- // if you see it open
- No CVEs, no named malware/trojan family, and no listing on established bad/trojan-port reference lists (e.g., garykessler.net) were found. SANS ISC tracks port 182 among ports monitored for background internet scanning (isc.sans.edu/data/port/182), consistent with routine opportunistic scan traffic rather than a known targeted campaign; specific scanner counts are live telemetry and not quoted as fixed facts. Aggregator-site risk labels (e.g., 'low risk,' 'uses encryption') are unsourced and treated as unverified.
About port 182/tcp.
Port 182/tcp is registered with IANA under the service name audit, with the description "Unisys Audit SITP," assignee and contact listed as Gil Greenbaum, and a blank reference field — no RFC or other IANA reference document exists for this assignment (IANA Service Name and Transport Protocol Port Number Registry, accessed 2026-07-11). The same service name, description, and assignee/contact are duplicated on the UDP row (182/udp), so the port carries a dual TCP/UDP assignment; Registration Date, Modification Date, Service Code, and Assignment Notes are all blank in the IANA source, consistent with an old legacy well-known-port entry that predates IANA's later date-tracking columns rather than a data-entry omission. Beyond the bare registry label, no RFC, protocol specification, or credible technical writeup describing what "Unisys Audit SITP" actually does on the wire could be located; the description strongly implies an audit-logging function tied to Unisys' historical SITP environment (presumably a Unisys mainframe/legacy-systems interconnect), but that reading is inference from the name, not a documented fact. A cluster of low-quality port-lookup aggregator sites restate the IANA string and then append generic, unsourced boilerplate ("used for compliance logging," "low risk," "uses encryption") that is not corroborated by any primary source and is treated here as unverified filler rather than fact. SANS Internet Storm Center tracks port 182 among the ports it monitors for background internet scanning, indicating it receives routine opportunistic scan traffic like most low-numbered ports, but no CVEs, malware family, or targeted-campaign association were found, and it does not appear on established bad/trojan-port reference lists.
- IANA assignment
audit— "Unisys Audit SITP"; reference (blank — no RFC cited in IANA registry); assignee/contact Gil Greenbaum [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv- Dual registration
- identical service name/description/assignee/contact on the 182/udp row; all other fields also blank on that row [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Registration Date / Modification Date / Service Code / Unauthorized Use Reported / Assignment Notes
- blank in the IANA registry (old legacy assignment, not a fabricated omission) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Range class
- well-known (0–1023)
Common software using this port
none identified; only the IANA registration itself was found, no current daemon/product documented
Exposure/scanning
SANS ISC tracks port 182 among ports monitored for background internet scanning, consistent with routine low-numbered-port scan noise; no CVEs or named malware tied to this port; not on garykessler.net's bad/trojan-port list
- Primary protocol use
- no RFC/spec/technical writeup found beyond the bare IANA label; likely an audit-logging function tied to Unisys legacy systems, but unconfirmed [Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
- Risk-classification claims ("low risk," "uses encryption") from aggregator sites are unsourced and not corroborated by any primary/technical documentation [Unknown] — https
- //ipfyi.com/port/182/
About port 182/udp.
Port 182/udp is registered with IANA under the service name audit, described only as "Unisys Audit SITP," with both the assignee and contact fields listing Gil_Greenbaum. The registry's Registration Date, Modification Date, and Reference (RFC) columns are all blank for this row, and no RFC or public protocol specification for this service was located beyond that one-line label — the entry is dually registered on both 182/tcp and 182/udp with identical service name and description, which is a common IANA pattern for legacy vendor assignments that predate a firm tcp/udp split. "SITP" most plausibly ties back to Unisys's Sperry-lineage mainframe/OS 2200 environment, but no vendor documentation, product manual, or open-source implementation referencing an "Audit SITP" service on port 182 could be confirmed, so the exact wire protocol and its purpose remain unverified beyond the registry label itself. Empirically the port is very rarely seen open: Nmap's nmap-services frequency table puts udp/182 at roughly 0.0003 probability of being open on a scanned host, and SANS Internet Storm Center's live port-182 activity log shows only low, sporadic scan traffic consistent with generic internet background noise rather than a targeted campaign. No CVE, malware family, or trojan-port reference was found associated with this port across the sources checked, so any exposure risk assessment here is necessarily provisional rather than a documented finding.
- IANA assignment
- service name
audit, description "Unisys Audit SITP," assignee/contact[Gil_Greenbaum], Registration Date/Modification Date/Reference all blank in the registry [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv - Dual registration
- identical service name/description registered on 182/tcp as well as 182/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency udp/182 ≈ 0.000297 (tcp/182 ≈ 0.000038) — very rarely seen open [Likely] — https://svn.nmap.org/nmap-exp/tudor/nsock-iocp/nmap-services
Primary use
legacy Unisys-specific audit/logging service ("SITP"); no independent spec or vendor doc located beyond the IANA label
Common software
none identified in current mainstream software or open-source projects; third-party port-lookup aggregators only echo the IANA label with no independent evidence of live deployment
Malware/CVE association
none found against garykessler.net's bad-ports list or Trend Micro's trojan-port reference [Unknown] — https://www.garykessler.net/library/bad_ports.html, https://docs.trendmicro.com/all/ent/officescan/v10.5/en-us/osce_10.5_olhcl/osce_topics/what_are_trojan_ports_.htm
- Scanning activity
- SANS ISC port-182 activity log (checked 2026-07-11) shows low, sporadic scan-source counts consistent with generic internet background noise, not a targeted campaign; figures are a live snapshot and will drift day to day [Likely] — https://isc.sans.edu/data/port/182
- Analyst note
- obsolete single-vendor legacy assignment; a responsive udp/182 is uncommon and worth noting but is not currently tied to any documented exploit or malware.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| audit | UDP | Unisys Audit SITP | 0.03% |
| audit | TCP | Unisys Audit SITP | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.