HoneyLabs

UDP traffic

Datagrams matching asn:11814 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

11

Datagrams

3

Source addresses

1

Networks

1

Countries

10

Destination ports

Traffic by type

Unrecognised

11 datagrams from 3 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 5060/udp

·.j2·wY·^·]7U iB·Fx?5·G;e·s3·Dv*Ra\aX6z6=Xn·eWTz·M9Rk· P·.EyY·Z5y2kti(LW:1·6

payload bytes
00000000  1b 2e 6a 32 0f 77 59 19  5e 07 5d 37 55 0d 69 42  |..j2.wY.^.]7U.iB|
00000010  14 46 78 3f 35 1e 47 3b  65 1f 73 33 0f 44 76 2a  |.Fx?5.G;e.s3.Dv*|
00000020  52 61 5c 61 58 36 7a 36  3d 58 6e 12 65 57 54 7a  |Ra\aX6z6=Xn.eWTz|
00000030  1d 4d 39 52 6b 00 0d 50  1f 01 03 2e 45 79 59 18  |.M9Rk..P....EyY.|
00000040  5a 35 79 32 6b 74 69 28  4c 57 3a 31 1a 36        |Z5y2kti(LW:1.6|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
Memcached11211/udp2110,000 to 51,000
mDNS5353/udp112 to 10
SSDP1900/udp1130.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
174.138.216.234AS11814 Distributel Communications LimitedCAUnrecognised92026-10-11 04:41
66.49.208.237AS11814 Distributel Communications LimitedCAUnrecognised12026-10-06 01:01
172.97.151.195AS11814 Distributel Communications LimitedCAUnrecognised12026-10-10 05:03

Latest datagrams