HoneyLabs

UDP traffic

Datagrams matching asn:212512 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

7

Datagrams

4

Source addresses

1

Networks

1

Countries

4

Destination ports

Traffic by type

Service queries

2 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest NTP datagram, to 123/udp

· ·

payload bytes
00000000  e3 00 0a f8 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000010  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000020  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|

Other services

5 datagrams from 4 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 6379/udp

OPTIONS sip:nm SIP/2.0 Via: SIP/2.0/TCP nm;branch=foo From: <sip:nm@nm>;tag=root To: <sip:nm2@nm2> Call-ID: 50000 CSeq: 42 OPTIONS Max-Forwards: 70 Content-Length: 0 Contact: <sip:nm@nm> Accept: application/sdp

payload bytes
00000000  4f 50 54 49 4f 4e 53 20  73 69 70 3a 6e 6d 20 53  |OPTIONS sip:nm S|
00000010  49 50 2f 32 2e 30 0d 0a  56 69 61 3a 20 53 49 50  |IP/2.0..Via: SIP|
00000020  2f 32 2e 30 2f 54 43 50  20 6e 6d 3b 62 72 61 6e  |/2.0/TCP nm;bran|
00000030  63 68 3d 66 6f 6f 0d 0a  46 72 6f 6d 3a 20 3c 73  |ch=foo..From: <s|
00000040  69 70 3a 6e 6d 40 6e 6d  3e 3b 74 61 67 3d 72 6f  |ip:nm@nm>;tag=ro|
00000050  6f 74 0d 0a 54 6f 3a 20  3c 73 69 70 3a 6e 6d 32  |ot..To: <sip:nm2|
00000060  40 6e 6d 32 3e 0d 0a 43  61 6c 6c 2d 49 44 3a 20  |@nm2>..Call-ID: |
00000070  35 30 30 30 30 0d 0a 43  53 65 71 3a 20 34 32 20  |50000..CSeq: 42 |
00000080  4f 50 54 49 4f 4e 53 0d  0a 4d 61 78 2d 46 6f 72  |OPTIONS..Max-For|
00000090  77 61 72 64 73 3a 20 37  30 0d 0a 43 6f 6e 74 65  |wards: 70..Conte|
000000a0  6e 74 2d 4c 65 6e 67 74  68 3a 20 30 0d 0a 43 6f  |nt-Length: 0..Co|
000000b0  6e 74 61 63 74 3a 20 3c  73 69 70 3a 6e 6d 40 6e  |ntact: <sip:nm@n|
000000c0  6d 3e 0d 0a 41 63 63 65  70 74 3a 20 61 70 70 6c  |m>..Accept: appl|
000000d0  69 63 61 74 69 6f 6e 2f  73 64 70 0d 0a 0d 0a     |ication/sdp....|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
NTP123/udp21556.9

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
45.82.78.105AS212512 Detai Prosperous Technologies LimitedDENTP32026-10-08 03:09
45.82.78.102AS212512 Detai Prosperous Technologies LimitedDESIP22026-10-07 16:50
45.82.78.100AS212512 Detai Prosperous Technologies LimitedDESIP12026-10-10 23:42
45.82.78.103AS212512 Detai Prosperous Technologies LimitedDESIP12026-10-07 10:31

Latest datagrams