394
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No confirmed modern software or deployment uses embl-ndt on port 394; it is a legacy, name-only IANA registration with no evidence of legitimate contemporary traffic, so an open/responsive port 394 should be investigated as anomalous rather than expected.
- // analyst note
- A responsive port 394/tcp has no known legitimate modern explanation — treat it as a fingerprinting curiosity, scanning artifact, or possible anomaly and investigate rather than assume normal service.
- // if you see it open
- No CVEs, malware associations, or documented exploitation are known for this port. It is a legacy, name-only IANA registration with no confirmed modern deployment; port-lookup aggregator sites merely mirror the bare IANA entry rather than reporting real sightings. Because it has no confirmed legitimate use today, any open/responsive port 394 should be treated as anomalous and investigated rather than assumed to be a live embl-ndt service.
About port 394/tcp.
Port 394/tcp is registered with IANA as embl-ndt ("EMBL Nucleic Data Transfer"), but no protocol specification or confirmed modern deployment exists for it, so a responsive port 394 should be treated as anomalous rather than expected on the public internet.
The IANA registry lists the assignment dual-registered on both 394/tcp and 394/udp, with assignee/contact [Peter_Gad], a blank Reference field (no RFC cited), and no registration date populated. EMBL refers to the European Molecular Biology Laboratory, placing this as a bioinformatics-era name registration.
No public protocol specification, RFC, or technical write-up describing how embl-ndt actually works could be found. The name-only registration gives a description but not a defined wire protocol, which is itself notable — many legacy IANA entries from this era were reserved for internal lab tooling that was never broadly documented or deployed.
Web research turned up no vendor documentation, blog posts, forum threads, or scanning/honeypot reports naming specific software that generates traffic on port 394 today. Third-party port-lookup aggregator sites (e.g. speedguide-style directories) only mirror the bare IANA entry rather than reporting observed real-world usage, so they are not treated as independent confirmation.
Given the sparse, undocumented nature of the assignment, any traffic seen on port 394 — whether inbound scans or an unexpected open listener — most plausibly reflects broad internet background-radiation scanning rather than an actively deployed embl-ndt service, and warrants investigation rather than assumption of legitimate use.
- IANA assignment
embl-ndt— "EMBL Nucleic Data Transfer"; reference (blank — no RFC cited); assignee/contact[Peter_Gad]; dual-registered 394/tcp + 394/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)- Range class
- well-known (0–1023) [Confirmed] — IANA registry
- Prevalence
- nmap-services open-frequency for 394/tcp ≈0.000000 [Confirmed] — nmap-services dataset (this site's own tooling); a recorded frequency of 0 reflects presence in the corpus with zero observed open instances, not an absence of data
- Related ports
- none specifically identified in research [Unknown]
Primary use
name-only registration for "EMBL Nucleic Data Transfer," a bioinformatics-era data-transfer use case tied to the European Molecular Biology Laboratory; no protocol spec publicly found
Other/unofficial uses
none confirmed by research [Unknown]
Security implications
no CVEs or malware associations documented; essentially no evidence of legitimate contemporary use, so an open instance should be treated as anomalous
Typically seen on
no confirmed deployments identified; anomaly if observed [Unknown]
- Analyst note
- A responsive port 394/tcp has no known legitimate modern explanation — treat it as a fingerprinting curiosity, scanning artifact, or possible anomaly and investigate rather than assume normal service.
About port 394/udp.
Port 394/udp is IANA-registered to embl-ndt ("EMBL Nucleic Data Transfer"), but no published RFC or vendor documentation describes an active implementation of it; the port does not belong on the public internet, and there is no evidence of any legitimate reason for a modern host to expose it externally today.
The IANA Service Name and Transport Protocol Port Number Registry lists embl-ndt as dual-registered on tcp and udp, assigned to Peter Gad, with a blank Reference column — meaning no RFC or specification was ever cited for the port. The name points to a data-transfer protocol tied to the European Molecular Biology Laboratory, but the registry itself documents no further protocol detail.
Targeted web research found no vendor documentation, blog posts, or forum/support threads reporting software currently using tcp/udp 394. The nmap-services corpus does record a scan-prevalence figure for this transport — an open-frequency of ≈0.000461 (this site's own tooling) — though no Shodan-style targeted-scan data specific to the port was located. A general port-lookup reference (auditmypc.com) lists UDP 394 with no known virus or Trojan association, and the port does not appear in common trojan/backdoor port compilations reviewed alongside it.
- IANA assignment
embl-ndt— "EMBL Nucleic Data Transfer"; reference (blank — no RFC cited); assignee Peter Gad; dual-registered 394/tcp + 394/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry line 782); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency for 394/udp ≈0.000461 [Confirmed] — nmap-services dataset (this site's own tooling)
- Related ports
- other legacy single-purpose IANA registrations from the same era; no specific cluster documented [Unknown]
Primary use
legacy IANA registration for EMBL (European Molecular Biology Laboratory) nucleic-acid data transfer; no published RFC/spec describing the wire protocol was found
Other/unofficial uses
none documented [Unknown]
Security implications
no known virus/Trojan association per a general port-lookup reference; does not appear in common trojan/backdoor port compilations checked
Typically seen on
no evidence of active deployment found; an open/responding port 394 today would be unexpected [Unknown]
- Analyst note
- treat unexpected traffic on 394/udp as anomalous given the lack of any documented active implementation — investigate rather than assume routine use.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| embl-ndt | UDP | EMBL Nucleic Data Transfer | 0.05% |
| embl-ndt | TCP | EMBL Nucleic Data Transfer | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.