HoneyLabs

UDP traffic

Datagrams matching asn:213520 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

3

Datagrams

1

Source addresses

1

Networks

1

Countries

3

Destination ports

Traffic by type

Unrecognised

3 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 11211/udp

B.·?\ >0·9[ds""@f$Fl`g·"^y|·Bs\·]]D9j·i}<Ea/g·pM(69·?*{8'}{·Z·w7D1!F·_·2F·"·,XL4v·^n·

payload bytes
00000000  42 2e 00 3f 5c 0d 3e 30  13 39 5b 64 73 22 22 40  |B..?\.>0.9[ds""@|
00000010  66 24 46 6c 60 67 06 22  5e 79 7c 02 42 73 5c 05  |f$Fl`g."^y|.Bs\.|
00000020  5d 5d 44 39 6a 02 69 7d  3c 45 61 2f 67 04 70 4d  |]]D9j.i}<Ea/g.pM|
00000030  28 36 39 08 1d 3f 2a 7b  38 27 7d 7b 1a 5a 00 77  |(69..?*{8'}{.Z.w|
00000040  37 44 31 21 46 1a 1e 02  5f 00 32 46 04 22 13 2c  |7D1!F..._.2F.".,|
00000050  58 4c 34 76 0c 5e 6e a7                           |XL4v.^n.|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SSDP1900/udp1130.8
Memcached11211/udp1110,000 to 51,000

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
131.123.13.17AS213520 Senko Digital LLCFIUnrecognised32026-10-09 08:18

Latest datagrams