Network port detail · UDP/TCP

310

Bhmds
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No documented protocol purpose or known software; officially registered but functionally dormant. No specific CVE or malware family confirmed tied to this port. SANS ISC observed only low-volume sporadic probe traffic as of 2026-07-18 (threat level green, no CVEs). With no confirmed legitimate use, any observed listener should be investigated as unidentified rather than assumed benign.
// analyst note
An open port 310 has no confirmed legitimate use case in current research; treat as unidentified and investigate rather than assume benign, though negligible real-world prevalence suggests it is rarely encountered at all.
[ 01 ] — Context

About port 310/tcp.

Updated  ·  Confidence: Low  ·  3 sources  ·  How this page is checked

Port 310/tcp is IANA-registered under the service name bhmds, but no RFC, vendor documentation, or public specification describes what the protocol actually does — so whether it belongs on the public internet cannot be determined from available sources, and it should be treated as unidentified/restricted-by-default until a specific listener is confirmed.

The IANA registry lists bhmds with description field that simply repeats the name, assignee and contact [John_Kelly], and an identical dual registration on 310/udp. The registration date, modification date, and reference columns are all blank in the live registry, so no formal specification or standards-track document governs this assignment.

No current or historical software product was found in this research pass that documents using port 310 for bhmds. Aggregator sites (SpeedGuide, t1shopper, ports.my-addr) only mirror the bare IANA name without adding technical detail, and generic "may have been used by a Trojan in the past" boilerplate on sites like auditmypc.com appears across nearly all ports in their database and is not treated as a sourced security claim.

Exposure
Unknown — no documented protocol purpose, software, or vendor use exists to determine an appropriate network placement; treat any observed listener as unidentified rather than assumed benign.
Prevalence signal
Nmap's nmap-services frequency file lists 310/tcp at ~0.000000 and 310/udp at ~0.000445, indicating the port is essentially never observed open in large scan corpora (https://svn.nmap.org/nmap/nmap-services).
Scanning telemetry
SANS Internet Storm Center's port tracker showed only low-volume, sporadic probe traffic against port 310 as of 2026-07-18, threat level "green," with no CVEs listed (https://isc.sans.edu/port.html?port=310) — a snapshot, not a stable historical fact.
Malware association
No specific malware or trojan family is confirmed tied to port 310 in this research pass; boilerplate aggregator claims are not reported as sourced fact.
IANA assignment
bhmds — description field repeats the name; assignee/contact [John_Kelly]; dual-registered 310/tcp + 310/udp, identical row [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Range class
well-known (0–1023)
Prevalence
nmap-services open-frequency 310/tcp ≈ 0.000000, 310/udp ≈ 0.000445 [Confirmed] — https://svn.nmap.org/nmap/nmap-services
Related ports
no closely related documented port cluster identified [Unknown]

Primary use

Unknown — no RFC, expanded description, or vendor documentation found explaining the protocol or what bhmds stands for [Unknown]

Other/unofficial uses

none documented [Unknown]

Security implications

no documented protocol purpose or known software; officially registered but functionally dormant; no specific CVE or malware family confirmed; SANS ISC observed only low-volume sporadic probe traffic as of 2026-07-18, threat level green

[Confirmed/Likely] — https://isc.sans.edu/port.html?port=310

Typically seen on

no known typical deployment identified [Unknown]

Analyst note
An open port 310 has no confirmed legitimate use case in current research; treat as unidentified and investigate rather than assume benign, though negligible real-world prevalence suggests it is rarely encountered at all.
[ 02 ] — Context

About port 310/udp.

Updated  ·  Confidence: Low  ·  4 sources  ·  How this page is checked

Port 310/udp is officially registered with IANA under the service name bhmds, but the registry supplies no protocol description, RFC, or vendor documentation beyond that bare label — what actually runs on this port is Unknown, so it cannot be assumed safe to expose and any live response deserves investigation rather than routine trust.

The IANA record lists description "bhmds" (unexpanded), assignee/contact "[John_Kelly]", and a blank Reference column; it is dual-registered on 310/tcp and 310/udp. This is a thin, decades-old assignment with no linked specification, and third-party port-database mirrors only echo the same IANA string without adding independent detail.

One secondary association exists but does not carry over cleanly: Wikipedia's port list notes TCP port 310 (not UDP) as unofficially tied to macOS Server Admin / AppleShare IP Web Administration. That entry is TCP-only in the source, so it is documented here only as a related historical note for the port number, not as the UDP protocol's function.

No malware or trojan association was found for 310/udp — AuditMyPC's port page explicitly flags "Virus/Trojan: No." No scanning writeups, honeypot reports, or CVEs mentioning 310/udp turned up in this pass, so its real-world exposure profile is undocumented rather than confirmed benign.

Exposure
Unknown — no documented protocol or vendor implementation exists for 310/udp, so there is no curated basis to classify it as internet-facing, restricted, or internal-only.
Malware association
None found; AuditMyPC lists UDP 310 as not associated with any virus or trojan.
Scanning notability
None found in this pass; 310/udp does not appear in general Shodan/mass-scan writeups or honeypot/threat-intel reporting reviewed.
Recommended posture
Because the registered service is undocumented and effectively unused, a live response on 310/udp should be treated as anomalous and investigated rather than assumed to be routine traffic.
IANA assignment
bhmds — description "bhmds" (no expansion given); assignee/contact "[John_Kelly]"; Reference column blank; dual-registered 310/tcp + 310/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=6
Range class
well-known (0–1023) [Confirmed]
Prevalence/scanning notability
Unknown — no nmap-services frequency data or mass-scan/honeypot reporting reviewed in this pass [Unknown]
Related ports
310/tcp (same IANA dual registration, service name bhmds) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

Unknown — no RFC, vendor documentation, or protocol specification found beyond the IANA registry string

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=6

Malware/trojan association

none found; AuditMyPC explicitly flags UDP 310 as "Virus/Trojan: No"

[Likely] — https://www.auditmypc.com/udp-port-310.asp

Typically seen on

Unknown — no documented deployments found [Unknown]

Secondary/unofficial association
TCP 310 (not UDP) linked by Wikipedia to macOS Server Admin / AppleShare IP Web Administration; TCP-side only, not verified for UDP [Likely] — https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
bhmds UDP — 0.04%
bhmds TCP — 0.00%
IANA name
bhmds
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.