390
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No primary-source software or protocol documentation ties any legitimate service to 390/tcp, so an open port 390 has no confirmed legitimate purpose and should be investigated rather than assumed benign.
- // analyst note
- A thinly-documented legacy IANA registration with no confirmed software behind it; an open port 390 has no established legitimate purpose and should be investigated if observed.
- // if you see it open
- No confirmed malware, trojan, or botnet C2 association found in trojan-port reference lists checked; no CVEs or scanning-campaign advisories specific to 390/tcp found. The only application claims trace to unsourced port-lookup aggregator sites, not vendor documentation, so an open port 390 has no established legitimate purpose and should be treated as anomalous if observed.
About port 390/tcp.
Port 390/tcp carries no confirmed protocol: IANA registers it only under the bare service name "uis," with no RFC, no protocol specification, and no documented software tying a real-world service to it, so it should not be treated as a legitimate public-facing service and any traffic on it is worth investigating rather than assuming benign.
IANA's Service Name and Transport Protocol Port Number Registry lists 390 as dual-registered on both TCP and UDP under the name "uis," assignee Ed Barron, with a blank Reference column — no defining RFC was ever published or cited for this assignment, and the registry gives no expansion of the "UIS" acronym.
No primary vendor documentation was found linking any real product to this port. Several low-authority port-lookup aggregator sites repeat a handful of unsourced claims — Unidata UDPROXY middleware, an alternate IBM AIX nfsd use, and an alternate Microsoft Exchange Server 5.5 LDAP listener (to avoid conflicting with Active Directory's LDAP on 389) — but none of these appear in Microsoft, IBM, or Unidata/Rocket Software documentation, so they are recorded here only as hearsay-tier, unverified sightings.
No malware, trojan, or botnet command-and-control association with 390/tcp was found in the trojan-port reference lists checked for this entry, and no mass-scanning campaigns or CVEs specific to this port surfaced.
- IANA assignment
uis— description "UIS"; reference column blank (no RFC cited); assignee/contact Ed Barron; dual-registered 390/tcp + 390/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=7- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency for 390/tcp ≈0.000000 [Confirmed] — nmap-services dataset (this site's own tooling); present in the dataset with zero observed open-frequency, not an absence of data
- Related ports
- 389/tcp (LDAP) — cited only because of the hedged, unverified Exchange 5.5 "alternate LDAP" aggregator claim
Primary use
Unknown — no protocol specification or RFC documents what "uis" does beyond the bare registry entry
Other/unofficial uses
Unidata UDPROXY; IBM AIX nfsd alternate use; Microsoft Exchange Server 5.5 alternate LDAP listener — all sourced only from port-lookup aggregator sites, not vendor documentation [Unknown/hedged] — https://tcp-udp-ports.bestvpnratings.com/port-390.htm, https://www.auditmypc.com/tcp-port-390.asp, https://portsmaster.net/port-390/
Security implications
no confirmed malware/trojan association found in trojan-port reference lists checked; no CVEs or scanning-campaign advisories specific to this port found [Confirmed — absence checked]
Typically seen on
Unknown — no primary-source software attribution confirmed [Unknown]
- Analyst note
- A thinly-documented legacy IANA registration with no confirmed software behind it; an open port 390 has no established legitimate purpose and should be investigated if observed.
About port 390/udp.
Port 390/udp is IANA-registered under the short name uis (contact: Ed Barron), but IANA publishes no description, RFC, or protocol specification for it, so its exact function cannot be confirmed from official sources; no legitimate service is confirmed to run here, so a responsive port should be treated as anomalous and investigated rather than exposed to the public internet.
The IANA registry jointly assigns both 390/tcp and 390/udp to uis, with the Reference column blank — this is a formally registered but sparsely documented service, not a widely deployed standard like DNS or HTTP. No primary vendor documentation for uis was located.
Secondary, non-authoritative port-lookup aggregators (not IANA, not vendor documentation) report that UDP 390 has been associated with Unidata's UDPROXY middleware, which provides IP connectivity between remote Unidata database systems, and separately with the IBM AIX nfsd daemon for NFS-related operations. These are repeated across SEO-style port databases without a primary citation.
These claims are aggregator-only, unsourced by any Unidata or IBM vendor documentation, and are treated here as hearsay-tier rather than adopted; no primary-source software or protocol documentation ties any legitimate service to 390/udp, so a responsive port has no confirmed legitimate purpose and should be investigated rather than assumed benign — mirroring the conservative treatment on the 390/tcp side of this page.
- IANA assignment
uis— description "UIS"; reference (blank); assignee Ed Barron; dual-registered 390/tcp + 390/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 773-774- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency for 390/udp ≈0.000478 [Confirmed] — nmap-services dataset (this site's own tooling)
- Related ports
- 2049/tcp,udp (NFS), 111/tcp,udp (rpcbind, used by NFS) — plausible NFS-adjacency given the hedged, unverified AIX
nfsdaggregator claim, not confirmed
Primary use
Unknown — IANA publishes no RFC or protocol description for uis; formally registered but undocumented
Other/unofficial uses
Unidata UDPROXY middleware and IBM AIX nfsd-related NFS traffic — aggregator-sourced only, not vendor-confirmed [Unknown/hedged] — https://tcp-udp-ports.bestvpnratings.com/port-390.htm, http://ports.my-addr.com/tcp_port-udp_port-application-and-description.php?port=390
Security implications
no confirmed malware/trojan association found; auditmypc.com's own verdict line for 390/udp reads "Virus / Trojan: No" [Confirmed] — auditmypc.com (https://www.auditmypc.com/udp-port-390.asp); UDP services generally receive less scanning/audit attention than TCP, a generic caution [Unknown]
Typically seen on
Unknown — no confirmed deployment context; possible Unidata or AIX NFS-adjacent hosts per unverified community sources
- Analyst note
- A sparsely documented registered port with no confirmed legitimate public use case; treat unexpected exposure as worth investigating rather than assuming benign.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| uis | UDP | — | 0.05% |
| uis | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.