Network port detail · UDP/TCP

84

Ctf
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Low-grade, opportunistic reconnaissance only — SANS ISC records a green (non-elevated) threat level as of mid-2026. No CVEs are filed against the CTF protocol itself, and no malware family or C2 framework is specifically documented as preferring this port. Because 84 is in the well-known range (0–1023) but carries no familiar service, HTTP served here may receive less firewall scrutiny than port 80; MITRE ATT&CK T1571 (Non-Standard Port) is the applicable technique, though port 84 is not named in public threat-actor reporting. Practical risk is low unless HTTP is served here without access controls.
// analyst note
A responsive port 84 is almost always HTTP on a non-standard port, not the registered CTF protocol — fingerprint the banner before assuming the IANA service.
[ 01 ] — Context

About port 84/tcp.

Updated  ·  Confidence: Medium

Port 84/tcp is registered with IANA as ctf with the description "Common Trace Facility," assignee Hugh Thomas, and a blank reference field — the registration is dual-listed on TCP and UDP with identical metadata. "Common Trace Facility" is an event-tracing and diagnostic-logging mechanism (the name and acronym predate the port-registry era and appear in older distributed-systems and mainframe tracing contexts), but no RFC or other IANA reference document is cited for the assignment, and no widely deployed commercial or open-source software is documented as actually speaking the CTF protocol on this port in the wild. For an analyst, the registered service is effectively dormant: what actually answers on port 84 across the public internet is HTTP. Shodan's port breakdown shows the dominant banner on 84/tcp is "Tengine" (the Nginx-derived web server originated at Taobao/Alibaba), with on the order of ~160k banners indexed — a pattern consistent with Chinese hosting operators running HTTP on an alternate, non-standard port rather than any official CTF traffic. SANS ISC records only low-grade, opportunistic reconnaissance against the port (a green, non-elevated threat level as of mid-2026), with no CVEs filed against the CTF protocol itself and no malware family or C2 framework specifically documented as preferring it. Because port 84 sits in the well-known range (0–1023) yet carries no familiar service, operators who serve HTTP here may apply less firewall scrutiny than they would to port 80 — MITRE ATT&CK T1571 (Non-Standard Port) is the applicable framing, though port 84 is not called out in any public threat-actor reporting. Practical risk for most networks is low unless HTTP is being served on this port without access controls.

IANA assignment
ctf — "Common Trace Facility"; reference (blank — no RFC cited in IANA registry); assignee [Hugh_Thomas]; dual-registered 84/tcp + 84/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
Shodan indexes ~160,301 banners on 84/tcp globally, dominated by the "Tengine" HTTP banner — a minor alternate-HTTP-port tier [Confirmed] — Shodan ports data
Registration/modification dates
blank in the IANA source CSV — not recorded [Confirmed]
Related ports
adjacent alternate-HTTP ports (e.g. 83/tcp, also Tengine-heavy in Shodan data)

Primary use

Common Trace Facility — an event-tracing / diagnostic-logging assignment; no RFC is publicly associated and the registered protocol is effectively dormant in public traffic

[Likely] — IANA registry (xhtml/csv)

Other/unofficial uses

de-facto HTTP via Tengine (Alibaba/Nginx fork), reflecting operators running HTTP on a non-standard port; no named software implements CTF on this port

[Likely] — Shodan port breakdown, tengine.taobao.org

Security implications

low-grade opportunistic scanning (SANS ISC green/non-elevated, mid-2026); no CVEs against the CTF protocol; no malware/C2 specifically documented; T1571 Non-Standard Port is the relevant technique for HTTP served here without scrutiny

[Likely] — SANS ISC, MITRE ATT&CK T1571

Typically seen on

HTTP servers (frequently Tengine) running on a non-standard port; the registered CTF service is rarely if ever observed

Analyst note
A responsive port 84 is almost always HTTP on a non-standard port, not the registered CTF protocol — fingerprint the banner before assuming the IANA service.
[ 02 ] — Context

About port 84/udp.

Updated  ·  Confidence: Medium

Port 84/udp is registered with IANA as ctf with the description "Common Trace Facility," assignee Hugh Thomas, and a blank reference field. The assignment is dual-registered: 84/tcp and 84/udp share the identical service name and description, so neither transport is the "primary" one in the registry — both carry the same ctf label. The IANA registry lists no RFC, no registration date, and no modification date for this entry; those columns are blank and stay blank rather than being filled with a guess. "Common Trace Facility" reads as a protocol for tracing and logging events in distributed systems, but the registry cites no defining document, and no currently maintained or widely deployed software is documented as using 84/udp for that purpose. Modern distributed-tracing toolchains (for example LTTng / the Linux Trace Toolkit lineage) rely on kernel mechanisms or entirely different transports and do not reference this assignment, so the registration is best understood as historical and effectively dormant. For an analyst, port 84 is unremarkable: it sits in the system / well-known range (0–1023), is blocked by default on most firewall configurations, and is absent from Wikipedia's well-known-ports table. No malware family, trojan, or active scanning campaign is documented against 84/udp, and third-party port references (such as AuditMyPC) list its virus/trojan status as "No." A responsive 84/udp is therefore most likely a custom or legacy application using the number opportunistically rather than any standardized Common Trace Facility deployment.

IANA assignment
ctf — "Common Trace Facility"; reference (blank — no RFC cited in IANA registry); assignee Hugh Thomas; dual-registered 84/tcp + 84/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry; the IANA Service Name and Transport Protocol Port Number Registry line 237
Range class
well-known / system ports (0–1023) [Confirmed]
Registration date / modification date
blank in the IANA registry — stays null, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 237
Prevalence / practical status
effectively dormant; omitted entirely from the Wikipedia well-known-ports table [Likely] — https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
Related ports
84/tcp (identical ctf registration)

Primary use

name-based "Common Trace Facility" assignment for tracing/logging events in distributed systems; no defining RFC; historical and effectively dormant

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=84

Common software

Unknown — no currently maintained or widely deployed package is documented using 84/udp for Common Trace Facility; modern tracing systems (LTTng / Linux Trace Toolkit) use kernel mechanisms or other transports [Unknown]

Security implications

no known malware, trojan, or active exploit/scanning campaign associated with 84/udp as of mid-2026; AuditMyPC lists virus/trojan status "No"; firewall-blocked by default in most configs

[Likely] — https://www.auditmypc.com/udp-port-84.asp

Typically seen on

not a routinely observed service; a responsive 84/udp is most likely a custom/legacy application using the number opportunistically

Analyst note
The IANA assignment exists but no active protocol ecosystem uses 84/udp; treat an open port 84 as a custom/legacy listener, not a standardized Common Trace Facility deployment.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ctf UDP Common Trace Facility 0.06%
ctf TCP Common Trace Facility 0.03%
IANA name
ctf
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.