386
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — The registration is an obscure, undocumented legacy IANA assignment with no known active implementation, so legitimate traffic on 386/tcp is not expected on modern networks and an open port should be investigated rather than assumed benign.
- // analyst note
- The service name "asa" is coincidental and unrelated to Cisco's ASA firewall product line; do not assume Cisco ASA management traffic on this port.
- // if you see it open
- Essentially unused, 40+ year old legacy registration with no known active implementation. The name 'asa' is unrelated to Cisco's ASA (Adaptive Security Appliance) firewall line (Cisco's published ASA port reference does not list 386) and unrelated to IBM/Rational ClearCase, which uses port 371 for its albd_server process. No credible, dated scanning or threat-intel reporting specific to port 386 was found. Generic port-database sites return templated, non-specific boilerplate rather than real evidence, so no software attribution is made.
About port 386/tcp.
Port 386/tcp carries the IANA-registered service name asa ("ASA Message Router Object Def."), an obscure legacy registration with no documented active implementation; it has no legitimate reason to be open on the public internet or on a modern network, and unsolicited traffic on it should be treated as anomalous rather than as evidence of a running service.
The IANA Service Name and Transport Protocol Port Number Registry lists 386 as dual-registered on both TCP and UDP under the identical service name and description, with Steve Laitinen recorded as the assignee/contact. The Reference column is blank — no RFC or specification is cited — and no registration or modification date is recorded in the registry.
The name asa predates and is unrelated to Cisco's ASA (Adaptive Security Appliance) firewall line; Cisco's own published ASA port reference does not list 386 for any management or service function, so any inference linking this port to Cisco ASA devices would rest on the acronym alone. It is also distinct from Rational/IBM ClearCase, whose albd_server process uses TCP/UDP 371, a separate and sometimes-confused assignment.
No credible, dated sighting of real-world software using port 386 was found. Generic "port lookup" sites returned templated boilerplate (including virus-flag language reused verbatim across unrelated ports) rather than specific evidence, so this entry does not attribute any application to the port.
- IANA assignment
asa— "ASA Message Router Object Def."; reference (blank — no RFC cited); assignee Steve_Laitinen; dual-registered 386/tcp + 386/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)- Range class
- well-known (0–1023) [Confirmed] — IANA registry
- Prevalence
- nmap-services open-frequency 386/tcp ≈ 0.000000 (not observed open); 386/udp ≈ 0.000741 (negligible) [Confirmed] — https://raw.githubusercontent.com/nmap/nmap/master/nmap-services
- Related ports
- 371/tcp+udp (IBM/Rational ClearCase
albd_server, name/acronym-adjacent but unrelated) [Confirmed] — HCL VersionVault / IBM ClearCase docs
Primary use
no documented, currently-active protocol use; the "ASA Message Router Object Def." registration is an obscure legacy assignment with no surviving specification found
Other/unofficial uses
none credibly documented [Unknown]
Security implications
no dated scanning/threat-intel reporting (e.g. SANS ISC, malware-family port lists) specifically calling out port 386 was found; it does not appear on major malware/trojan port lists reviewed
Typically seen on
no known legitimate deployments; anomalous if observed [Unknown]
- Analyst note
- The service name "asa" is coincidental and unrelated to Cisco's ASA firewall product line; do not assume Cisco ASA management traffic on this port.
About port 386/udp.
Port 386/udp has no known active service today; it is a dormant legacy IANA registration, and an open or responsive host on this port should be treated as anomalous rather than expected traffic. IANA lists it under the service name asa, described only as "ASA Message Router Object Def.," with no accompanying RFC or public protocol specification found anywhere in this research pass.
The registry entry is otherwise unremarkable: assignee Steve Laitinen, a blank Reference column, and dual registration on both 386/tcp and 386/udp under the same name. That blank reference is typical of older IANA entries made before the registry required a citable specification, and it should be reported as blank rather than filled with a guessed RFC.
No vendor documentation, forum thread, or software product was found using this port, so no specific application can be credibly attributed to observed traffic. One port-lookup aggregator (AuditMyPC) explicitly flags UDP 386 as not tied to any known virus or trojan, and no CVE or named malware family references this port.
Given the absence of any documented legitimate deployment, the most likely explanation for traffic on 386/udp is background internet scanning noise rather than a real "ASA Message Router" service in production use. Analysts encountering it should treat it as a low-confidence anomaly worth a closer look rather than as evidence of a specific product or exploit.
- IANA assignment
asa— "ASA Message Router Object Def."; reference (blank — no RFC cited); assignee Steve Laitinen; dual-registered 386/tcp + 386/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=7)- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- not surfaced by this research pass (no nmap-services or telemetry figure available) [Unknown]
- Related ports
- 386/tcp (same
asaname, dual-registered) [Confirmed]
Primary use
formal legacy IANA registration; no protocol specification or evidence of active current deployment was found
Other/unofficial uses
none found in this research pass; abstained rather than guessed [Unknown]
Security implications
no CVE or malware family confirmed tied to this port; likely background scanning noise given the lack of any active known service
Typically seen on
no known typical host — dormant legacy registration rather than a deployed service [Likely]
- Analyst note
- An open port 386/udp is not tied to any known legitimate application; treat it as a low-confidence anomaly (possible scan noise or decoy) rather than a recognizable service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| asa | UDP | ASA Message Router Object Def. | 0.07% |
| asa | TCP | ASA Message Router Object Def. | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.