HoneyLabs

UDP traffic

Datagrams matching asn:14618 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

5

Datagrams

5

Source addresses

1

Networks

1

Countries

3

Destination ports

Traffic by type

Other services

1 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

OPTIONS sip:0.0.0.0 SIP/2.0 Via: SIP/2.0/UDP 0.0.0.0:5555;rport;branch=z9hG4bKI4Wxk0fAW6JUdiIrinztjsRbl Max-Forwards: 70 From: <sip:user@0.0.0.0>;tag=2TD1HQEM18jnLslO6eJb To: <sip:user@0.0.0.0> Call-ID: AxBYMw88dILtKW3FGWTh8iDB74utSGX2B9hK813LMe69RGismmU4NjZczpzX CSeq: 1234 OPTIONS User-Agent

payload bytes
00000000  4f 50 54 49 4f 4e 53 20  73 69 70 3a 30 2e 30 2e  |OPTIONS sip:0.0.|
00000010  30 2e 30 20 53 49 50 2f  32 2e 30 0d 0a 56 69 61  |0.0 SIP/2.0..Via|
00000020  3a 20 53 49 50 2f 32 2e  30 2f 55 44 50 20 30 2e  |: SIP/2.0/UDP 0.|
00000030  30 2e 30 2e 30 3a 35 35  35 35 3b 72 70 6f 72 74  |0.0.0:5555;rport|
00000040  3b 62 72 61 6e 63 68 3d  7a 39 68 47 34 62 4b 49  |;branch=z9hG4bKI|
00000050  34 57 78 6b 30 66 41 57  36 4a 55 64 69 49 72 69  |4Wxk0fAW6JUdiIri|
00000060  6e 7a 74 6a 73 52 62 6c  0d 0a 4d 61 78 2d 46 6f  |nztjsRbl..Max-Fo|
00000070  72 77 61 72 64 73 3a 20  37 30 0d 0a 46 72 6f 6d  |rwards: 70..From|
00000080  3a 20 3c 73 69 70 3a 75  73 65 72 40 30 2e 30 2e  |: <sip:user@0.0.|
00000090  30 2e 30 3e 3b 74 61 67  3d 32 54 44 31 48 51 45  |0.0>;tag=2TD1HQE|
000000a0  4d 31 38 6a 6e 4c 73 6c  4f 36 65 4a 62 0d 0a 54  |M18jnLslO6eJb..T|
000000b0  6f 3a 20 3c 73 69 70 3a  75 73 65 72 40 30 2e 30  |o: <sip:user@0.0|
000000c0  2e 30 2e 30 3e 0d 0a 43  61 6c 6c 2d 49 44 3a 20  |.0.0>..Call-ID: |
000000d0  41 78 42 59 4d 77 38 38  64 49 4c 74 4b 57 33 46  |AxBYMw88dILtKW3F|
000000e0  47 57 54 68 38 69 44 42  37 34 75 74 53 47 58 32  |GWTh8iDB74utSGX2|
000000f0  42 39 68 4b 38 31 33 4c  4d 65 36 39 52 47 69 73  |B9hK813LMe69RGis|

Unrecognised

4 datagrams from 4 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 1701/udp

·-·! "·"·`·4·-·(·Ϩ·:·(·8· P·5·5·L·8·bh·G^#·^A·>U·I·Ll·G{ǂ·q·_·O·K+X·f·4+A-z·^·"·

payload bytes
00000000  0e a3 cc e7 b5 2d a8 8d  00 00 00 00 00 00 00 00  |.....-..........|
00000010  21 20 22 08 00 00 00 00  00 00 01 a8 22 00 00 60  |! "........."..`|
00000020  02 00 00 34 01 01 08 04  0e a3 cc e7 b5 2d a8 8d  |...4.........-..|
00000030  03 00 00 0c 01 00 00 17  80 0e 01 00 03 00 00 08  |................|
00000040  02 00 00 05 03 00 00 08  03 00 00 0c 00 00 00 08  |................|
00000050  04 00 00 0e 00 00 00 28  02 03 04 03 cf a8 05 3a  |.......(.......:|
00000060  03 00 00 0c 01 00 00 17  80 0e 01 00 03 00 00 08  |................|
00000070  05 00 00 01 00 00 00 08  03 00 00 0c 28 00 01 08  |............(...|
00000080  00 0e 00 00 e8 c8 1d 38  d5 09 50 a5 35 dc c2 8a  |.......8..P.5...|
00000090  88 35 eb 4c bc 38 11 62  68 9d c8 f3 47 5e 23 13  |.5.L.8.bh...G^#.|
000000a0  1e 5e 41 7f 3e 55 96 49  00 d7 4c 6c 8e ed 10 47  |.^A.>U.I..Ll...G|
000000b0  7b c7 82 87 d0 71 f7 5f  e8 a3 4f d6 f6 b7 4b 2b  |{....q._..O...K+|
000000c0  58 a1 b2 66 f1 87 34 2b  41 2d 7a 89 cd 5e b5 22  |X..f..4+A-z..^."|
000000d0  b2 6c 99 67 81 a0 96 27  d2 53 45 2b 41 36 16 70  |.l.g...'.SE+A6.p|
000000e0  d8 4f d8 65 cc 3d 07 21  51 9c 67 a4 77 f9 2d 97  |.O.e.=.!Q.g.w.-.|
000000f0  a6 8a 09 1f fe b7 8b 21  87 da b2 58 95 d9 cb f8  |.......!...X....|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
Memcached11211/udp2210,000 to 51,000

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
44.220.185.189AS14618 Amazon.com, Inc.USUnrecognised12026-10-10 14:49
100.29.192.5AS14618 Amazon.com, Inc.USUnrecognised12026-10-10 16:10
44.220.188.56AS14618 Amazon.com, Inc.USUnrecognised12026-10-10 13:54
100.29.192.88AS14618 Amazon.com, Inc.USUnrecognised12026-10-10 16:10
100.29.192.76AS14618 Amazon.com, Inc.USSIP12026-10-10 18:52

Latest datagrams