HoneyLabs

UDP traffic

Datagrams matching asn:211298 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

319

Datagrams

174

Source addresses

1

Networks

1

Countries

66

Destination ports

Traffic by type

Service queries

64 datagrams from 40 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest SNMP datagram, to 161/udp

0>·0· g·0·0·N·0·

payload bytes
00000000  30 3e 02 01 03 30 11 02  04 09 67 89 95 02 03 00  |0>...0....g.....|
00000010  ff e3 04 01 04 02 01 03  04 10 30 0e 04 00 02 01  |..........0.....|
00000020  00 02 01 00 04 00 04 00  04 00 30 14 04 00 04 00  |..........0.....|
00000030  a0 0e 02 04 4e bd b1 f1  02 01 00 02 01 00 30 00  |....N.........0.|

Other services

47 datagrams from 36 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest DTLS datagram, to 443/udp

·y·y·_·3·h+ ·3k*ܵ·)u·:Lb·{T·%ʃ·+·/· · ·,·0̨̩·7· · · ·

payload bytes
00000000  16 fe fd 00 00 00 00 00  00 00 00 00 85 01 00 00  |................|
00000010  79 00 00 00 00 00 00 00  79 fe fd 5f 07 f5 ef 33  |y.......y.._...3|
00000020  0e 68 2b 09 d4 33 6b 2a  dc b5 e8 d6 0f 29 75 86  |.h+..3k*.....)u.|
00000030  3a 4c 62 d8 d6 7b 54 8e  25 ca 83 00 00 00 18 c0  |:Lb..{T.%.......|
00000040  ac c0 ae c0 2b c0 2f c0  09 c0 13 c0 0a c0 14 c0  |....+./.........|
00000050  2c c0 30 cc a9 cc a8 01  00 00 37 00 0d 00 16 00  |,.0.......7.....|
00000060  14 04 03 05 03 06 03 08  07 08 04 08 05 08 06 04  |................|
00000070  01 05 01 06 01 ff 01 00  01 00 00 0a 00 0a 00 08  |................|
00000080  00 1d 00 17 00 18 00 19  00 0b 00 02 01 00 00 17  |................|
00000090  00 00                                             |..|

QUIC

94 datagrams from 85 sources

Initial packets of HTTP/3 connections, decoded on the sensor.

Latest QUIC datagram, to 443/udp

QUIC v1 Initial alpn=http/0.9,http/1.0,spdy/1,spdy/2,spdy/3,stun.turn,stun.nat-discovery,h2c,webrtc,c-webrtc,ftp,imap,pop3,managesieve,coap,co

Unrecognised

114 datagrams from 60 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 37700/udp

8f·6CK·y·

payload bytes
00000000  38 66 01 36 43 4b 81 af  79 00 00 00 00 00        |8f.6CK..y.....|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SNMPv2161/udp16156.3
DNS53/udp8828 to 54
NTP123/udp87556.9
Portmap111/udp667 to 28
WS-Discovery3702/udp8310 to 500
SSDP1900/udp +15330.8
TFTP19876/udp +12260

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

QUIC clients (JA4)

QUIC transport parameters

QUIC versions

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
193.163.125.139AS211298 Driftnet LtdGBUnrecognised62026-10-10 22:23
193.163.125.178AS211298 Driftnet LtdGBUnrecognised52026-10-10 17:59
193.163.125.170AS211298 Driftnet LtdGBUnrecognised52026-10-10 22:56
193.163.125.166AS211298 Driftnet LtdGBSOAP52026-10-11 08:43
193.163.125.151AS211298 Driftnet LtdGBUnrecognised52026-10-11 05:37
193.163.125.116AS211298 Driftnet LtdGBUnrecognised52026-10-09 03:09
193.163.125.241AS211298 Driftnet LtdGBSOAP52026-10-08 22:52
193.163.125.173AS211298 Driftnet LtdGBSNMP52026-10-11 02:48
193.163.125.167AS211298 Driftnet LtdGBUnrecognised52026-10-11 06:50
193.163.125.130AS211298 Driftnet LtdGBUnrecognised42026-10-10 23:43
193.163.125.179AS211298 Driftnet LtdGBSNMP42026-10-11 08:43
193.163.125.175AS211298 Driftnet LtdGBUnrecognised42026-10-08 09:32
193.163.125.137AS211298 Driftnet LtdGBUnrecognised42026-10-10 14:10
193.163.125.231AS211298 Driftnet LtdGBUnrecognised42026-10-11 02:36
193.163.125.150AS211298 Driftnet LtdGBTFTP42026-10-09 10:35
193.163.125.165AS211298 Driftnet LtdGBUnrecognised42026-10-11 02:40
193.163.125.153AS211298 Driftnet LtdGBSOAP42026-10-10 11:43
193.163.125.143AS211298 Driftnet LtdGBUnrecognised32026-10-07 22:02
193.163.125.234AS211298 Driftnet LtdGBUnrecognised32026-10-07 13:46
193.163.125.219AS211298 Driftnet LtdGBUnrecognised32026-10-07 11:59

Latest datagrams