HoneyLabs

UDP traffic

Datagrams matching asn:272786 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

10

Datagrams

1

Source addresses

1

Networks

1

Countries

8

Destination ports

Traffic by type

Unrecognised

10 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 1434/udp

·.dr\Q·E;PZP]v·R· ·:3·AD\·_·7@v)·G,a·|;RY1Y+I]5cs<·&R_j.xI@/ 6Y%}·AR[s,·< < |xV·

payload bytes
00000000  1e 2e 64 72 5c 51 03 45  3b 50 5a 50 5d 76 07 52  |..dr\Q.E;PZP]v.R|
00000010  18 04 09 1a 15 07 3a 33  16 41 44 5c 19 5f 12 37  |......:3.AD\._.7|
00000020  40 76 29 1c 47 2c 61 02  7c 3b 52 59 31 59 2b 49  |@v).G,a.|;RY1Y+I|
00000030  5d 35 63 73 3c 1e 26 52  5f 6a 2e 78 49 40 2f 09  |]5cs<.&R_j.xI@/.|
00000040  36 59 25 7d 05 06 00 02  41 52 5b 73 2c 07 3c 09  |6Y%}....AR[s,.<.|
00000050  3c 20 7c 78 56 b5                                 |< |xV.|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SSDP1900/udp1130.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
209.14.88.121AS272786 X99 INTERNETBRUnrecognised102026-10-10 20:05

Latest datagrams