Network port detail · UDP/TCP

140

Emfis-data
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No virus/trojan association reported (auditmypc.com); GRC Port Authority entry is minimal with no vulnerability/backdoor history. No port-140-specific Shodan exposure statistics were found in this pass, so real-world open-host volume is not measured.
[ 01 ] — Context

About port 140/tcp.

Updated  ·  Confidence: Medium

Port 140/tcp is registered with IANA under the service name emfis-data, described simply as "EMFIS Data Service," and dual-registered with an identical entry on 140/udp. The current live IANA Service Name and Transport Protocol Port Number Registry carries no assignee, contact, registration date, or Reference value for this row — the assignment is a bare name-and-description pair with no attached specification. Historically, the now-obsolete RFC 1340 ("Assigned Numbers," October 1992) did list this exact same 140/tcp and 140/udp assignment with the citation tag "[GB7]," but RFC 1340 itself has long since been superseded by later Assigned Numbers RFCs and by the online registry, which carries forward no Reference value today — so that historical citation should not be read as a live IANA reference. EMFIS is described, via a secondhand community-forum summary rather than a primary source, as "Experimentelles Führungsinformationssystem" — an experimental West German military command/information system built at FGAN, originally run on a Siemens mainframe under BS2000, later fitted with a TCP/IP interface onto ARPANET so it could be reached via an ASCII terminal. No current or historical third-party software implementing emfis-data was found beyond that one legacy system, and no port-140-specific Shodan exposure statistics were located; general port-scanning sources (auditmypc.com, GRC's Port Authority) report no virus/trojan association and no notable security history for this port, consistent with a narrow, effectively retired legacy protocol rather than an actively deployed or actively abused one.

IANA assignment
emfis-data — "EMFIS Data Service"; dual-registered 140/tcp + 140/udp; assignee, contact, registration date, and Reference all blank in the current registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-358; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023)
Prevalence
no nmap-services or Shodan-specific open-frequency data for port 140 was located in this pass [Unknown]
Related ports
140/udp (identical dual registration of emfis-data) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-358

Primary use

EMFIS Data Service — the historical West German military "Experimentelles Führungsinformationssystem" (FGAN, Siemens BS2000 mainframe, later given a TCP/IP/ARPANET interface); detail is secondhand (primary thread returned HTTP 403)

[Likely] — https://www.pcreview.co.uk/threads/emfis.1719125/

Other/unofficial uses

none identified — no current or historical third-party software or daemon implementing emfis-data was found beyond the single legacy EMFIS system [Unknown]

Security implications

no virus/trojan association reported for TCP port 140; GRC's Port Authority entry is minimal with no vulnerability or backdoor history listed; internet-wide exposure volume not measured in this pass

[Likely] — https://www.auditmypc.com/tcp-port-140.asp; https://www.grc.com/port_140.htm

Typically seen on

legacy/historical EMFIS-related military systems only; a responsive port 140 on a modern host is not expected and would be anomalous rather than a normal service [Likely]

Historical reference
RFC 1340 (Oct 1992, now obsolete) lists this same assignment with citation tag "[GB7]" for both 140/tcp and 140/udp — a real historical document, not a current live IANA Reference value [Confirmed] — https://datatracker.ietf.org/doc/html/rfc1340
[ 02 ] — Context

About port 140/udp.

Updated  ·  Confidence: Medium

Port 140/udp is registered with IANA as emfis-data, described simply as "EMFIS Data Service," with the Assignee, Contact, Registration Date, Modification Date, and Reference columns all blank in the current registry — a dual registration shared with 140/tcp, which carries the identical service name and description. EMFIS stands for "Experimentelles Führungsinformationssystem" (Experimental Command/Management Information System), a legacy German military information system reportedly developed at FGAN and originally run on a Siemens BS2000 mainframe, with a later TCP/IP interface added so ARPANET-style terminal clients could reach it. The IANA port-140 assignment (both transports) appears to formalize the network port used by that data service. No RFC or other reference document is cited in the registry for either the TCP or UDP entry, and no registration or modification date is recorded. No actively maintained modern client or server software implementing emfis-data was identified, consistent with this being a historical, largely retired assignment rather than something seen in current deployments. From a security-monitoring standpoint, port 140/udp is not flagged as a known trojan or malware-associated port in available port-database sources, though as with any UDP port, internet-wide scans can report it "open|filtered" without a real listening service due to UDP's connectionless nature. An analyst encountering unexpected traffic on 140/udp should treat it as an anomaly worth investigating rather than as a signature of any specific known threat, since no historical malware family is documented as using it.

IANA assignment
emfis-data — "EMFIS Data Service"; reference (blank — no RFC cited in IANA registry); assignee/contact (blank); dual-registered 140/tcp + 140/udp, identical service name and description on both rows [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-358; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Range class
well-known (0–1023)
Prevalence
nmap-services observed open-frequency 140/udp ≈ 0.000692 — very low (roughly 7 in 10,000 scanned hosts in the nmap-services sample); the paired 140/tcp row carries a frequency of 0 (never observed open in the same sample) [Confirmed] — nmap-services dataset
Related ports
140/tcp (identical dual registration, same service name and description)

Primary use

legacy German military information system (EMFIS = "Experimentelles Führungsinformationssystem"), originally on a Siemens BS2000 mainframe with a later TCP/IP terminal interface; IANA's emfis-data assignment covers its network data service

[Likely] — https://www.pcreview.co.uk/threads/emfis.1719125/

Other/unofficial uses

none identified — no current client/server software found implementing emfis-data [Unknown]

Security implications

not flagged as a trojan/malware-associated port; auditmypc.com's port database lists "Virus/Trojan: No" for UDP 140, and clarifies that a historical red flag in such databases means a trojan used the port in the past, not that current malware uses it — no specific malware family found tied to 140/udp; general UDP open|filtered scan-ambiguity caveats apply

[Likely] — https://www.auditmypc.com/udp-port-140.asp

Typically seen on

no modern deployments identified; effectively a retired/legacy IANA assignment [Unknown]

Analyst note
An open port 140/udp is not a documented threat signature or common service in current environments — treat unexpected traffic on it as anomalous and investigate rather than assume malicious intent from any known family.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
emfis-data UDP EMFIS Data Service 0.07%
emfis-data TCP EMFIS Data Service 0.00%
IANA name
emfis-data
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.