HoneyLabs

UDP traffic

Datagrams matching asn:16735 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

12

Datagrams

6

Source addresses

1

Networks

1

Countries

11

Destination ports

Traffic by type

Other services

1 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SOCKS5 datagram, to 22997/udp

·4Vx·

payload bytes
00000000  05 00 ff ff 00 fe fe fe  fe fd fd fd fd 12 34 56  |..............4V|
00000010  78 07 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |x...............|
00000020  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000030  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000040  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000050  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000060  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000070  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000080  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000a0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000b0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000c0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000d0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000e0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000f0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|

Unrecognised

11 datagrams from 5 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 8080/udp

9.jZ=Cor(9n·s·w.·O·hf'%1k%·^*W(·1eX W·YF·LL·zM·"k·I·45"·

payload bytes
00000000  39 2e 6a 5a 3d 43 6f 72  28 39 6e 07 73 06 77 2e  |9.jZ=Cor(9n.s.w.|
00000010  01 07 08 4f 1c 68 66 27  25 31 6b 25 1d 5e 2a 57  |...O.hf'%1k%.^*W|
00000020  28 15 31 65 58 20 57 00  59 46 08 4c 4c 7f 7a 4d  |(.1eX W.YF.LL.zM|
00000030  06 03 1c 22 6b 02 49 10  34 35 22 98              |..."k.I.45".|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
Memcached11211/udp1110,000 to 51,000

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
201.48.108.11AS16735 ALGAR TELECOM S/ABRUnrecognised72026-10-10 19:47
189.37.69.143AS16735 ALGAR TELECOM S/ABRUnrecognised12026-10-09 22:41
189.37.70.88AS16735 ALGAR TELECOM S/ABRSOCKS512026-10-09 05:08
189.37.69.44AS16735 ALGAR TELECOM S/ABRUnrecognised12026-10-10 10:45
187.32.8.65AS16735 ALGAR TELECOM S/ABRUnrecognised12026-10-07 13:02
189.37.77.63AS16735 ALGAR TELECOM S/ABRUnrecognised12026-10-10 11:43

Latest datagrams