Network port detail · UDP/TCP

386

Asa
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — The registration is an obscure, undocumented legacy IANA assignment with no known active implementation, so legitimate traffic on 386/tcp is not expected on modern networks and an open port should be investigated rather than assumed benign.
// analyst note
The service name "asa" is coincidental and unrelated to Cisco's ASA firewall product line; do not assume Cisco ASA management traffic on this port.
// if you see it open
Essentially unused, 40+ year old legacy registration with no known active implementation. The name 'asa' is unrelated to Cisco's ASA (Adaptive Security Appliance) firewall line (Cisco's published ASA port reference does not list 386) and unrelated to IBM/Rational ClearCase, which uses port 371 for its albd_server process. No credible, dated scanning or threat-intel reporting specific to port 386 was found. Generic port-database sites return templated, non-specific boilerplate rather than real evidence, so no software attribution is made.
[ 01 ] — Context

About port 386/tcp.

Updated  ·  Confidence: Low

Port 386/tcp carries the IANA-registered service name asa ("ASA Message Router Object Def."), an obscure legacy registration with no documented active implementation; it has no legitimate reason to be open on the public internet or on a modern network, and unsolicited traffic on it should be treated as anomalous rather than as evidence of a running service.

The IANA Service Name and Transport Protocol Port Number Registry lists 386 as dual-registered on both TCP and UDP under the identical service name and description, with Steve Laitinen recorded as the assignee/contact. The Reference column is blank — no RFC or specification is cited — and no registration or modification date is recorded in the registry.

The name asa predates and is unrelated to Cisco's ASA (Adaptive Security Appliance) firewall line; Cisco's own published ASA port reference does not list 386 for any management or service function, so any inference linking this port to Cisco ASA devices would rest on the acronym alone. It is also distinct from Rational/IBM ClearCase, whose albd_server process uses TCP/UDP 371, a separate and sometimes-confused assignment.

No credible, dated sighting of real-world software using port 386 was found. Generic "port lookup" sites returned templated boilerplate (including virus-flag language reused verbatim across unrelated ports) rather than specific evidence, so this entry does not attribute any application to the port.

IANA assignment
asa — "ASA Message Router Object Def."; reference (blank — no RFC cited); assignee Steve_Laitinen; dual-registered 386/tcp + 386/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)
Range class
well-known (0–1023) [Confirmed] — IANA registry
Prevalence
nmap-services open-frequency 386/tcp ≈ 0.000000 (not observed open); 386/udp ≈ 0.000741 (negligible) [Confirmed] — https://raw.githubusercontent.com/nmap/nmap/master/nmap-services
Related ports
371/tcp+udp (IBM/Rational ClearCase albd_server, name/acronym-adjacent but unrelated) [Confirmed] — HCL VersionVault / IBM ClearCase docs

Primary use

no documented, currently-active protocol use; the "ASA Message Router Object Def." registration is an obscure legacy assignment with no surviving specification found

[Likely] — searched web sources, no primary spec located

Other/unofficial uses

none credibly documented [Unknown]

Security implications

no dated scanning/threat-intel reporting (e.g. SANS ISC, malware-family port lists) specifically calling out port 386 was found; it does not appear on major malware/trojan port lists reviewed

[Unknown] — searched web sources, none found

Typically seen on

no known legitimate deployments; anomalous if observed [Unknown]

Analyst note
The service name "asa" is coincidental and unrelated to Cisco's ASA firewall product line; do not assume Cisco ASA management traffic on this port.
[ 02 ] — Context

About port 386/udp.

Updated  ·  Confidence: Medium

Port 386/udp has no known active service today; it is a dormant legacy IANA registration, and an open or responsive host on this port should be treated as anomalous rather than expected traffic. IANA lists it under the service name asa, described only as "ASA Message Router Object Def.," with no accompanying RFC or public protocol specification found anywhere in this research pass.

The registry entry is otherwise unremarkable: assignee Steve Laitinen, a blank Reference column, and dual registration on both 386/tcp and 386/udp under the same name. That blank reference is typical of older IANA entries made before the registry required a citable specification, and it should be reported as blank rather than filled with a guessed RFC.

No vendor documentation, forum thread, or software product was found using this port, so no specific application can be credibly attributed to observed traffic. One port-lookup aggregator (AuditMyPC) explicitly flags UDP 386 as not tied to any known virus or trojan, and no CVE or named malware family references this port.

Given the absence of any documented legitimate deployment, the most likely explanation for traffic on 386/udp is background internet scanning noise rather than a real "ASA Message Router" service in production use. Analysts encountering it should treat it as a low-confidence anomaly worth a closer look rather than as evidence of a specific product or exploit.

IANA assignment
asa — "ASA Message Router Object Def."; reference (blank — no RFC cited); assignee Steve Laitinen; dual-registered 386/tcp + 386/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=7)
Range class
well-known (0–1023) [Confirmed]
Prevalence
not surfaced by this research pass (no nmap-services or telemetry figure available) [Unknown]
Related ports
386/tcp (same asa name, dual-registered) [Confirmed]

Primary use

formal legacy IANA registration; no protocol specification or evidence of active current deployment was found

[Likely] — IANA registry page

Other/unofficial uses

none found in this research pass; abstained rather than guessed [Unknown]

Security implications

no CVE or malware family confirmed tied to this port; likely background scanning noise given the lack of any active known service

[Likely] — AuditMyPC, SpeedGuide

Typically seen on

no known typical host — dormant legacy registration rather than a deployed service [Likely]

Analyst note
An open port 386/udp is not tied to any known legitimate application; treat it as a low-confidence anomaly (possible scan noise or decoy) rather than a recognizable service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
asa UDP ASA Message Router Object Def. 0.07%
asa TCP ASA Message Router Object Def. 0.00%
IANA name
asa
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.