HoneyLabs

UDP traffic

Datagrams matching asn:211298 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

57

Datagrams

45

Source addresses

1

Networks

1

Countries

30

Destination ports

Traffic by type

Service queries

7 datagrams from 7 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

DNS query A example.com

payload bytes
00000000  96 3b 01 20 00 01 00 00  00 00 00 00 07 65 78 61  |.;. .........exa|
00000010  6d 70 6c 65 03 63 6f 6d  00 00 01 00 01           |mple.com.....|

Other services

7 datagrams from 7 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest DTLS datagram, to 12346/udp

·y·y·Jv/·i·$_z·!{·k;V·iK·+·/· · ·,·0̨̩·7· · · ·

payload bytes
00000000  16 fe fd 00 00 00 00 00  00 00 00 00 85 01 00 00  |................|
00000010  79 00 00 00 00 00 00 00  79 fe fd 4a 76 2f 16 69  |y.......y..Jv/.i|
00000020  b3 e6 fa f5 ba c1 89 24  5f 7a 06 14 21 7b a2 8c  |.......$_z..!{..|
00000030  6b 3b 56 c7 ec c0 d2 18  69 4b 08 00 00 00 18 c0  |k;V.....iK......|
00000040  ac c0 ae c0 2b c0 2f c0  09 c0 13 c0 0a c0 14 c0  |....+./.........|
00000050  2c c0 30 cc a9 cc a8 01  00 00 37 00 0d 00 16 00  |,.0.......7.....|
00000060  14 04 03 05 03 06 03 08  07 08 04 08 05 08 06 04  |................|
00000070  01 05 01 06 01 ff 01 00  01 00 00 0a 00 0a 00 08  |................|
00000080  00 1d 00 17 00 18 00 19  00 0b 00 02 01 00 00 17  |................|
00000090  00 00                                             |..|

QUIC

18 datagrams from 18 sources

Initial packets of HTTP/3 connections, decoded on the sensor.

Latest QUIC datagram, to 443/udp

QUIC v1 Initial alpn=http/0.9,http/1.0,spdy/1,spdy/2,spdy/3,stun.turn,stun.nat-discovery,h2c,webrtc,c-webrtc,ftp,imap,pop3,managesieve,coap,co

Unrecognised

25 datagrams from 16 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 88/udp

j·e0·b· ·U0S·P·NM·0·0·krbtgt·NM·20261011024929Z·X$·0·0·

payload bytes
00000000  6a 81 65 30 81 62 a1 03  02 01 05 a2 03 02 01 0a  |j.e0.b..........|
00000010  a4 81 55 30 53 a0 07 03  05 00 50 00 00 00 a2 04  |..U0S.....P.....|
00000020  1b 02 4e 4d a3 17 30 15  a0 03 02 01 00 a1 0e 30  |..NM..0........0|
00000030  0c 1b 06 6b 72 62 74 67  74 1b 02 4e 4d a5 11 18  |...krbtgt..NM...|
00000040  0f 32 30 32 36 31 30 31  31 30 32 34 39 32 39 5a  |.20261011024929Z|
00000050  a7 06 02 04 58 24 d1 30  a8 0e 30 0c 02 01 12 02  |....X$.0..0.....|
00000060  01 11 02 01 17 02 01 03                           |........|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp2228 to 54
SNMPv2161/udp226.3
Portmap111/udp117 to 28
NTP123/udp11556.9

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

QUIC clients (JA4)

QUIC transport parameters

QUIC versions

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
193.163.125.170AS211298 Driftnet LtdGBUnrecognised32026-10-10 22:56
193.163.125.151AS211298 Driftnet LtdGBUnrecognised32026-10-11 03:22
193.163.125.137AS211298 Driftnet LtdGBUnrecognised32026-10-10 14:10
193.163.125.178AS211298 Driftnet LtdGBUnrecognised22026-10-10 17:59
193.163.125.237AS211298 Driftnet LtdGBUnrecognised22026-10-10 12:20
193.163.125.165AS211298 Driftnet LtdGBUnrecognised22026-10-11 02:40
193.163.125.139AS211298 Driftnet LtdGBUnrecognised22026-10-10 22:23
193.163.125.161AS211298 Driftnet LtdGBSun RPC22026-10-10 11:03
193.163.125.251AS211298 Driftnet LtdGBUnrecognised22026-10-10 23:02
193.163.125.168AS211298 Driftnet LtdGBSun RPC12026-10-10 19:06
185.247.137.167AS211298 Driftnet LtdGBQUIC12026-10-10 06:01
87.236.176.249AS211298 Driftnet LtdGBQUIC12026-10-10 11:41
193.163.125.128AS211298 Driftnet LtdGBUnrecognised12026-10-10 11:12
193.163.125.142AS211298 Driftnet LtdGBUnrecognised12026-10-11 02:28
193.163.125.173AS211298 Driftnet LtdGBUnrecognised12026-10-11 02:48
195.96.139.223AS211298 Driftnet LtdGBQUIC12026-10-10 11:43
193.163.125.153AS211298 Driftnet LtdGBDTLS12026-10-10 11:43
195.96.139.242AS211298 Driftnet LtdGBQUIC12026-10-10 11:43
185.247.137.106AS211298 Driftnet LtdGBQUIC12026-10-10 18:26
193.163.125.118AS211298 Driftnet LtdGBUnrecognised12026-10-10 09:43

Latest datagrams