36
Summary
- // if you see it open
- No port-36-specific malware, trojan, or notable internet-scanning activity found in public threat-intelligence sources or common trojan-port tables as of June 2026. Because the port is unassigned, any observed traffic on 36/tcp in production should be treated as unexpected and investigated, but no specific known exploit or malware family targets it.
- // analyst note
- An open/active port 36 has no legitimate well-known meaning — treat as unexpected and investigate (decoy, misconfiguration, or custom/unauthorized service).
About port 36/tcp.
Port 36/tcp is listed as Unassigned in the IANA Service Name and Transport Protocol Port Number Registry: it carries no service name, no description beyond "Unassigned," no assignee, no registration or modification date, and a blank reference field. The paired 36/udp entry is identically Unassigned, so neither transport has ever been allocated a well-known service. Historically this has always been the case — RFC 1340 (Assigned Numbers, July 1992), the printed precursor to the modern online registry, likewise carries no entry for port 36. It is worth distinguishing port 36 from its immediate neighbour, port 35/tcp, which RFC 1340 designates as "any private printer server"; secondary reference sites occasionally drift that label onto port 36, but the primary sources keep port 35 and 36 separate and leave 36 blank. Because the port sits inside the well-known range (0–1023) yet has no assignment, there is no standardized client or server that should bind to it, and no widely documented software uses 36/tcp as a default or primary port. For an analyst the practical reading is simple: traffic on 36/tcp has no legitimate well-known meaning, so an open or active port 36 in a production environment is unexpected by definition and is worth investigating rather than dismissing. As of June 2026 no port-36-specific malware, trojan, or notable internet-scanning campaign appears in public threat-intelligence sources or common trojan-port tables, and the port does not feature in Shodan's top scanned-port reports — so while unexpected traffic warrants a look, there is no known exploit or malware family that singles out this port.
- IANA assignment
- Unassigned — no service name, blank description ("Unassigned"), blank assignee, blank reference; same status on 36/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (CSV line 79; 36/udp line 80)
- Range class
- well-known (0–1023) [Confirmed]
- Related ports
- neighbour port 35/tcp (private printer server); the surrounding low well-known range
Primary use
none — no IANA-assigned service; no standardized protocol use
Common software
Unknown — no widely documented software binds to 36/tcp as a primary/default port [Unknown]
Security implications
no port-36-specific malware, trojan, or notable scanning activity found in public sources as of June 2026; because the port is unassigned, any observed traffic should be treated as unexpected and investigated, but no specific exploit targets it
- Historical note
- RFC 1340 (Assigned Numbers, 1992) carries no entry for port 36; not to be confused with port 35/tcp, "any private printer server" [Confirmed] — RFC 1340
- Analyst note
- An open/active port 36 has no legitimate well-known meaning — treat as unexpected and investigate (decoy, misconfiguration, or custom/unauthorized service).
About port 36/udp.
Port 36/udp carries no formal IANA service-name assignment: the IANA Service Name and Transport Protocol Port Number Registry leaves the service-name, assignee, contact, reference, registration-date and modification-date columns blank for this entry, and the paired 36/tcp row is identically Unassigned. The only descriptive text historically attached to port 36 is the generic placeholder "any private printer server" — a legacy artifact of early IANA numbering practice (the cluster of "any private …" descriptions associated with Jon Postel), not a live protocol specification. No RFC defines a service on this port, and no widely deployed commercial or open-source software is documented to bind specifically to UDP/36 in normal operation. For an analyst the practical meaning is simple: there is no standard service to expect here. Open-source threat intelligence searched through June 2026 turned up no CVEs, malware campaigns, or exploit kits specifically targeting UDP/36, and the port sees negligible legitimate traffic on the public internet. Because the only "description" on record is an unspecified placeholder rather than a real protocol, any host found listening on UDP/36 should be treated as non-standard and investigated — there is no recognized service whose presence would justify the exposure. General UDP risks (spoofed-source / stateless scanning, and amplification if an unintended responder is left listening) apply, but no port-36-specific threat pattern is documented.
- IANA assignment
- none — service name, assignee, contact, reference, registration date and modification date are all blank; status Unassigned [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 80; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Range class
- well-known (0–1023) [Confirmed]
- Dual registration
- 36/tcp is also Unassigned (CSV line 79) — port 36 is Unassigned on both transports [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 79
- IANA reference
- blank — no RFC cited in the registry [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
- Related ports
- the low-numbered Unassigned cluster; contrast assigned well-known UDP services
Common software
Unknown — no documented commercial or open-source software is known to bind specifically to UDP/36 [Unknown]
Security implications
no CVEs, malware, or exploit kits specific to UDP/36 found in open sources (through June 2026); negligible legitimate internet traffic; any listener is non-standard and worth investigating; general UDP spoofing/amplification risks apply if a service is inadvertently left listening [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt, https://www.speedguide.net/port.php?port=36
Typically seen on
nothing standard — a responsive UDP/36 is an anomaly / possible non-standard service
- Legacy description
- "any private printer server" — a generic placeholder from early IANA practice (Postel-era), not a formal service name or active protocol [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Analyst note
- There is no IANA-assigned service on UDP/36; the only descriptive text is a legacy "any private printer server" placeholder. Treat any listener as non-standard and investigate.