HoneyLabs

UDP traffic

Datagrams matching asn:211680 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

67

Datagrams

7

Source addresses

1

Networks

1

Countries

39

Destination ports

Traffic by type

Service queries

28 datagrams from 7 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest SNMP datagram, to 161/udp

0)·public·VZ·]·0·0·+·

payload bytes
00000000  30 29 02 01 00 04 06 70  75 62 6c 69 63 a0 1c 02  |0).....public...|
00000010  04 56 5a dc 5d 02 01 00  02 01 00 30 0e 30 0c 06  |.VZ.]......0.0..|
00000020  08 2b 06 01 02 01 01 01  00 05 00                 |.+.........|

Other services

7 datagrams from 4 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

OPTIONS sip:nzeliNQl@<HONEYPOT> SIP/2.0 Via: SIP/2.0/UDP 45.156.129.166:55875;branch=mtNAdi.7725660277;rport;alias From: sip:ZElXVCoj@45.156.129.166:55875;tag=05513667 To: sip:vkinDDMW@<HONEYPOT> Call-ID: 6522710525@45.156.129.166 CSeq: 1 OPTIONS Contact: sip:ZbtRKAnm@45.156.129.166:55875 Con

Payload bytes withheld: they contain the sensor's address.

Unrecognised

31 datagrams from 6 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 500/udp

·D ·=U·! "·"·0·,·(·M·H ·e(n·DP·_·ƹ·'·X·0·9·c"·<6·YS'·O·&·yZ~·o x·y·n·3⟮·+·WO:BM·ڑ·o\·(·%·Ox·

payload bytes
00000000  a0 a5 44 20 97 08 3d 55  00 00 00 00 00 00 00 00  |..D ..=U........|
00000010  21 20 22 08 00 00 00 00  00 00 01 88 22 00 00 30  |! "........."..0|
00000020  00 00 00 2c 01 01 00 04  03 00 00 0c 01 00 00 0c  |...,............|
00000030  80 0e 01 00 03 00 00 08  02 00 00 05 03 00 00 08  |................|
00000040  03 00 00 0c 00 00 00 08  04 00 00 0e 28 00 01 08  |............(...|
00000050  00 0e 00 00 cf 4d e8 04  0e 48 0a cc ee 65 28 6e  |.....M...H...e(n|
00000060  a4 44 50 97 c4 5f 82 c6  b9 b8 c2 9a 9c 27 aa dc  |.DP.._.......'..|
00000070  58 af 30 da 39 01 63 22  00 3c 36 c7 c0 83 c1 84  |X.0.9.c".<6.....|
00000080  a6 a4 ba 59 53 27 9c 4f  05 26 d7 cf c1 fe e4 12  |...YS'.O.&......|
00000090  d1 79 5a 7e 1d a9 1b 6f  09 78 f2 df 79 19 6e 0f  |.yZ~...o.x..y.n.|
000000a0  33 e2 9f ae 93 2b 15 d3  57 4f 3a 42 4d d8 7f da  |3....+..WO:BM...|
000000b0  91 ca 6f 5c b0 b0 bf 14  28 f8 ee 04 b8 8f 25 16  |..o\....(.....%.|
000000c0  88 de 4f 78 16 86 a9 e5  5a 41 2b ad ce f5 d0 e3  |..Ox....ZA+.....|
000000d0  bb 78 21 c0 67 64 d9 a7  c5 bf 5b 82 2a fd 6e 0c  |.x!.gd....[.*.n.|
000000e0  21 ac 1c 79 77 e8 99 48  e7 04 62 1f 6d ab 6a 52  |!..yw..H..b.m.jR|
000000f0  16 47 34 3c 73 6b be af  c3 4b 03 63 35 ec 66 5e  |.G4<sk...K.c5.f^|

Peer-to-peer

1 datagrams from 1 source

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SNMPv2161/udp1956.3
RIPv1520/udp22131.24
TFTP69/udp +13160
Portmap111/udp117 to 28
mDNS5353/udp112 to 10
NTP123/udp11556.9
NetBIOS137/udp113.8
CLDAP389/udp1156 to 70
CharGEN19/udp11358.8
SSDP1900/udp1130.8
Memcached11211/udp1110,000 to 51,000
WS-Discovery3702/udp1110 to 500

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
45.156.129.85AS211680 Sistemas Informaticos, S.A.PTUnrecognised152026-10-08 02:52
45.156.129.87AS211680 Sistemas Informaticos, S.A.PTBitTorrent142026-10-08 02:51
45.156.129.86AS211680 Sistemas Informaticos, S.A.PTUnrecognised112026-10-08 02:50
45.156.129.88AS211680 Sistemas Informaticos, S.A.PTUnrecognised102026-10-08 02:52
45.156.129.165AS211680 Sistemas Informaticos, S.A.PTSNMP72026-10-08 05:37
45.156.129.166AS211680 Sistemas Informaticos, S.A.PTSNMP62026-10-08 05:37
45.156.129.164AS211680 Sistemas Informaticos, S.A.PTSNMP42026-10-08 05:37

Latest datagrams