417
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No confirmed application uses port 417/tcp, and the widely repeated CommView Remote Agent attribution is contradicted by the vendor's own documentation, so a responsive 417/tcp is anomalous and warrants investigation rather than being treated as routine traffic.
- // analyst note
- A responsive port 417 has no verified legitimate service behind it — investigate as an anomaly rather than assume the aggregator-site CommView attribution.
- // if you see it open
- No confirmed application or documented protocol runs on 417/tcp, and the one commonly repeated attribution (CommView Remote Agent) is contradicted by the vendor's own docs. No malware association is confirmed for this port — no named family, sample, CVE, or dated incident was found. An open 417/tcp is not expected in normal operation and should be treated as anomalous.
About port 417/tcp.
Port 417/tcp carries no confirmed service in practice; IANA registers the bare name "onmux" with no protocol specification and no software reliably documented to use it, so a responsive 417/tcp should be treated as anomalous rather than assumed to belong on the public internet.
IANA lists 417/tcp and 417/udp as "onmux" ("Onmux"), assigned to Stephen Hanna, with a blank Reference field — no RFC or published protocol document is cited, and none was found independently.
A claim circulates on low-authority port-database aggregator sites that TamoSoft's CommView Remote Agent uses port 417. Checking this against TamoSoft's own vendor documentation shows the product's actual default ports are 5050 (CommView Remote Agent) and 5051 (CommView Remote Agent for WiFi) — not 417 — so this attribution does not hold up and is not recorded as fact.
No malware association is confirmed for 417/tcp either: no named family, sample, CVE, or dated incident was found tying malware to this port. No scanning studies, honeypot datasets, or commonly-attacked-port lists were found flagging 417/tcp specifically.
- IANA assignment
onmux— "Onmux"; reference blank; assignee Stephen_Hanna; dual-registered 417/tcp + 417/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- 0.000226 [Confirmed] — this site's own tooling
- Related ports
- 5050/tcp and 5051/tcp — TamoSoft CommView Remote Agent's actual documented default ports
Primary use
Unknown — no documented protocol specification for "onmux" beyond the bare IANA name registration
Other/unofficial uses
Unverified aggregator-site claim that TamoSoft CommView Remote Agent uses this port, contradicted by TamoSoft's own vendor docs specifying ports 5050/5051
Security implications
no confirmed application; the one repeated attribution is contradicted by primary vendor docs; no malware association is confirmed for 417/tcp
Typically seen on
no confirmed hosts or software; anomaly if seen
- Analyst note
- A responsive port 417 has no verified legitimate service behind it — investigate as an anomaly rather than assume the aggregator-site CommView attribution.
About port 417/udp.
Port 417/udp carries onmux, a service name IANA registered to Stephen Hanna with no protocol specification, no RFC reference, and no documented real-world implementation. Because nothing legitimate is known to run on it, traffic on 417/udp is anomalous by default and the port has no business being exposed to the public internet.
IANA's Service Name and Transport Protocol Port Number Registry lists 417 as onmux ("Onmux") on both tcp and udp, assigned to Stephen Hanna. The Reference column — where IANA normally cites a defining RFC — is blank, and no Registration Date is recorded, meaning the entry is a bare name reservation rather than a documented protocol.
No protocol specification, vendor documentation, or open-source implementation of onmux could be located beyond the IANA listing itself. Searches across port-lookup aggregators (SpeedGuide, T1 Shopper, WintelGuy, AuditMyPC) and general web sources turned up no credible sighting of software that actually generates traffic on this port, so its practical use today is genuinely Unknown rather than merely obscure.
AuditMyPC's port database explicitly marks 417 as having no known virus or trojan association, and no other source ties the port to malware. That absence of a negative signal is not the same as a positive use case — it simply means 417/udp appears dormant rather than actively documented or actively abused.
- IANA assignment
onmux— "Onmux"; reference blank (no RFC cited); assignee Stephen Hanna [Stephen_Hanna]; dual-registered 417/tcp + 417/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- 0.000774 [Confirmed] — this site's own tooling
- Related ports
- none specifically documented as related; no modern cluster association identified [Unknown]
Primary use
Unknown — IANA registers the bare name onmux with no protocol specification published anywhere
Other/unofficial uses
none documented; active searching (vendor docs, forums, aggregator sites) surfaced no credible sighting of software using this port [Unknown]
Security implications
no malware/trojan association confirmed [Likely] — AuditMyPC; no protocol spec exists to validate traffic against, so activity here is anomalous [Confirmed absence of documentation]
Typically seen on
Unknown — no documented deployments or implementations found [Unknown]
- Analyst note
- An open or active 417/udp is undocumented anywhere beyond a bare IANA name reservation — treat it as anomalous and investigate rather than assume legitimate use.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| onmux | UDP | Meeting maker | 0.08% |
| onmux | TCP | Meeting maker | 0.02% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.