HoneyLabs

UDP traffic

Datagrams matching asn:16276 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

345

Datagrams

14

Source addresses

1

Networks

5

Countries

39

Destination ports

Traffic by type

Other services

334 datagrams from 10 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

OPTIONS sip:100@<HONEYPOT> SIP/2.0 Via: SIP/2.0/UDP 135.148.29.54:28760;branch=z9hG4bK-2041312579;rport Max-Forwards: 70 To: "sipvicious"<sip:100@1.1.1.1> From: "sipvicious"<sip:100@1.1.1.1>;tag=3035616662373834313363340132343832393636323135 User-Agent: friendly-scanner Call-ID: 36177417821625

Payload bytes withheld: they contain the sensor's address.

Unrecognised

11 datagrams from 4 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 30301/udp

A.WqhTQ=·}.r7\u]·uQ·1·z"<·%Jn4·8·} `N]aK·S·hH_t=1·n6!iX]·p1

payload bytes
00000000  41 2e 57 71 68 54 51 3d  00 7d 2e 72 37 5c 75 5d  |A.WqhTQ=.}.r7\u]|
00000010  0c 75 51 1e 31 05 0f 7a  22 3c 1d 25 4a 6e 34 0c  |.uQ.1..z"<.%Jn4.|
00000020  38 0c 7d 20 60 4e 5d 61  4b 0b 53 02 68 48 5f 74  |8.} `N]aK.S.hH_t|
00000030  3d 31 12 6e 36 21 69 58  5d 06 70 31              |=1.n6!iX].p1|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SSDP1900/udp3130.8
mDNS5353/udp112 to 10
Memcached11211/udp1110,000 to 51,000

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
135.148.29.54AS16276 OVH SASUSSIP1122026-10-11 04:06
198.244.200.163AS16276 OVH SASGBSIP702026-10-11 03:05
51.161.136.177AS16276 OVH SASAUSIP562026-10-11 03:09
51.161.57.3AS16276 OVH SASCASIP562026-10-10 14:23
5.39.125.103AS16276 OVH SASFRSIP132026-10-10 22:40
51.178.198.251AS16276 OVH SASFRSIP82026-10-11 03:06
167.114.107.175AS16276 OVH SASCAUnrecognised72026-10-07 14:11
51.38.221.109AS16276 OVH SASFRSIP62026-10-08 14:02
5.196.61.130AS16276 OVH SASFRSIP52026-10-11 02:51
5.135.106.85AS16276 OVH SASFRSIP42026-10-07 09:53
162.19.19.234AS16276 OVH SASFRSIP42026-10-09 21:58
51.75.24.26AS16276 OVH SASFRUnrecognised22026-10-08 17:15
51.161.33.215AS16276 OVH SASCAUnrecognised12026-10-10 11:37
151.80.60.145AS16276 OVH SASFRUnrecognised12026-10-10 14:23

Latest datagrams