HoneyLabs

UDP traffic

Datagrams matching asn:12876 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

271

Datagrams

15

Source addresses

1

Networks

2

Countries

40

Destination ports

Traffic by type

Service queries

78 datagrams from 5 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

DNS query TXT/CH version.bind

payload bytes
00000000  e2 8c 01 20 00 01 00 00  00 00 00 00 07 76 65 72  |... .........ver|
00000010  73 69 6f 6e 04 62 69 6e  64 00 00 10 00 03 00     |sion.bind......|

Other services

154 datagrams from 8 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5070/udp

OPTIONS sip:100@<HONEYPOT> SIP/2.0 Via: SIP/2.0/UDP 127.0.0.1:5063;branch=z9hG4bK3b470ea1 To: <sip:100@1.1.1.1> From: <sip:100@1.1.1.1>;tag=4ede08fc Call-ID: fc4d11f4ea6df60d CSeq: 1 OPTIONS Contact: <sip:a@127.0.0.1:5063> Content-Length: 0

Payload bytes withheld: they contain the sensor's address.

Unrecognised

36 datagrams from 2 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 8083/udp

·.&6&]·Z'%·N6·l]·,4<Y*@·V·wiD·C·

payload bytes
00000000  13 2e 26 36 26 5d 05 5a  27 25 1f 00 0f 4e 36 1e  |..&6&].Z'%...N6.|
00000010  0b 07 6c 5d 0b 2c 34 3c  59 2a 40 1f 56 0b 77 69  |..l].,4<Y*@.V.wi|
00000020  44 1d 43 fe                                       |D.C.|

Peer-to-peer

3 datagrams from 1 source

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp37228 to 54
mDNS5353/udp422 to 10
NetBIOS137/udp2313.8
SNMPv2161/udp1716.3
Memcached11211/udp2110,000 to 51,000
SSDP1900/udp1130.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
62.210.89.150AS12876 Scaleway SASFRUnrecognised362026-10-11 04:40
51.158.202.97AS12876 Scaleway SASNLSIP302026-10-10 22:19
51.158.202.6AS12876 Scaleway SASNLSIP302026-10-10 22:19
51.158.201.249AS12876 Scaleway SASNLSIP282026-10-10 22:19
51.158.205.153AS12876 Scaleway SASNLSIP282026-10-10 22:19
51.158.204.210AS12876 Scaleway SASNLSIP282026-10-10 22:19
62.210.90.215AS12876 Scaleway SASFRNetBIOS232026-10-11 00:37
51.158.205.203AS12876 Scaleway SASNLDNS202026-10-11 00:48
62.210.142.176AS12876 Scaleway SASFRDNS172026-10-10 16:28
62.210.142.61AS12876 Scaleway SASFRSNMP172026-10-08 17:39
163.172.205.45AS12876 Scaleway SASFRSIP42026-10-07 06:40
212.83.186.8AS12876 Scaleway SASFRSIP42026-10-08 19:46
163.172.53.219AS12876 Scaleway SASFRUnrecognised32026-10-11 02:58
163.172.31.144AS12876 Scaleway SASFRSIP22026-10-06 12:52
78.232.50.178AS12876 Scaleway SASFRDNS12026-10-10 23:51

Latest datagrams