HoneyLabs

UDP traffic

Datagrams matching asn:13489 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

1.7K

Datagrams

18

Source addresses

1

Networks

1

Countries

5

Destination ports

Traffic by type

Service queries

1 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest NetBIOS datagram, to 137/udp

NetBIOS node status query *

payload bytes
00000000  f5 d6 00 00 00 01 00 00  00 00 00 00 20 43 4b 41  |............ CKA|
00000010  41 41 41 41 41 41 41 41  41 41 41 41 41 41 41 41  |AAAAAAAAAAAAAAAA|
00000020  41 41 41 41 41 41 41 41  41 41 41 41 41 00 00 21  |AAAAAAAAAAAAA..!|
00000030  00 01                                             |..|

Unrecognised

3 datagrams from 3 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 43570/udp

·@xS·!-·Qϧ·>·K·r0B^·B·8`·_uf·:·#·#·9·d·te·u·ӑ·H·kR·h·c· ·J·y·作C *RW·L·tK·#7·j·*·O,· ·ڞF·

payload bytes
00000000  a3 40 78 53 f7 aa 8d be  21 2d f0 9d 51 cf a7 1c  |.@xS....!-..Q...|
00000010  3e e9 4b 8d 72 30 42 5e  be 87 c7 42 f0 15 38 60  |>.K.r0B^...B..8`|
00000020  d0 02 e8 b2 5f 75 66 fd  3a e7 e2 83 23 f5 d5 23  |...._uf.:...#..#|
00000030  0b 8d d9 d1 e2 d6 db 1f  14 39 94 8b a8 b9 64 07  |.........9....d.|
00000040  9a dd c8 1a e7 74 65 db  06 aa 13 f1 75 e4 98 d3  |.....te.....u...|
00000050  91 d7 e0 8f c6 48 d2 7f  a0 9e fd 13 e6 6b 52 07  |.....H.......kR.|
00000060  c2 68 87 8e ac 95 fe 63  ed 0f 09 9c d1 4a 90 08  |.h.....c.....J..|
00000070  79 f2 e4 bd 9c 43 20 2a  52 57 82 fe 91 4c ce 74  |y....C *RW...L.t|
00000080  4b 0f 23 ee b0 8d 37 c6  e3 6a e3 2a ea 01 4f 2c  |K.#...7..j.*..O,|
00000090  7f 0a e0 da 9e 46 c0 a0  17 94 45 91 84 97 51 c5  |.....F....E...Q.|
000000a0  a3 ce 38 1f 6c 8f 6e bd  fa 51 36 00 cf 0b 92 49  |..8.l.n..Q6....I|
000000b0  88 99 06 90 0b 71 da 59  4b 42 d1 eb 8d e0 c4 32  |.....q.YKB.....2|
000000c0  84 f5 aa 96 73 9c 72 1c  ac 46 d0 7d 13 01 05 68  |....s.r..F.}...h|
000000d0  42 df c2 a9 0d 5f db 21  bc 98 c1 de ee 17 8c 9e  |B...._.!........|
000000e0  b2 f3 0b 21 a9 e3 d3 da  37 84 05 08 be d1 c8 f6  |...!....7.......|
000000f0  b6 3a 20 88 b0 4e ab cd  0e 4f ab e9 a4 36 5e 59  |.: ..N...O...6^Y|

Peer-to-peer

1,743 datagrams from 14 sources

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
NetBIOS137/udp113.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
191.95.130.237AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent7162026-10-11 00:55
181.68.24.141AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent3672026-10-11 04:57
190.128.98.78AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent2082026-10-11 02:48
191.95.161.175AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent1572026-10-10 20:59
191.95.166.77AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent1062026-10-06 22:05
179.12.253.200AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent502026-10-09 15:07
179.12.190.175AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent442026-10-09 03:25
181.133.57.152AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent322026-10-09 09:09
177.255.199.91AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent292026-10-10 23:02
190.250.102.41AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent112026-10-09 02:30
181.138.13.120AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent102026-10-08 21:13
179.14.176.164AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent82026-10-10 00:04
191.95.131.62AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent42026-10-09 04:16
191.95.52.36AS13489 UNE EPM TELECOMUNICACIONES S.A.CONetBIOS12026-10-06 21:20
181.204.179.195AS13489 UNE EPM TELECOMUNICACIONES S.A.COUnrecognised12026-10-07 13:32
177.253.158.104AS13489 UNE EPM TELECOMUNICACIONES S.A.COUnrecognised12026-10-08 07:20
191.95.160.246AS13489 UNE EPM TELECOMUNICACIONES S.A.COBitTorrent12026-10-10 23:45
181.129.101.50AS13489 UNE EPM TELECOMUNICACIONES S.A.COUnrecognised12026-10-06 14:49

Latest datagrams