HoneyLabs

UDP traffic

Datagrams matching asn:396982 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

338

Datagrams

234

Source addresses

1

Networks

3

Countries

97

Destination ports

Traffic by type

Service queries

122 datagrams from 57 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

DNS query TXT/CH version.bind

payload bytes
00000000  34 ef 01 00 00 01 00 00  00 00 00 00 07 76 65 72  |4............ver|
00000010  73 69 6f 6e 04 62 69 6e  64 00 00 10 00 03 0a     |sion.bind......|

Other services

83 datagrams from 77 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest DTLS datagram, to 12446/udp

·6·*·*·|w@·"·ʬ d/·"d·0·/·

payload bytes
00000000  16 fe ff 00 00 00 00 00  00 00 00 00 36 01 00 00  |............6...|
00000010  2a 00 00 00 00 00 00 00  2a fe fd 00 00 00 00 7c  |*.......*......||
00000020  77 40 1e 8a c8 22 a0 a0  18 ff 93 08 ca ac 0a 64  |w@...".........d|
00000030  2f c9 22 64 bc 08 a8 16  89 19 30 00 00 00 02 00  |/."d......0.....|
00000040  2f 01 00                                          |/..|

Unrecognised

132 datagrams from 123 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 500/udp

·O,·P·4·(·$·p·$·p·$·p·$·p·$·p·$

payload bytes
00000000  f2 4f 2c dd 17 1c b3 d5  00 00 00 00 00 00 00 00  |.O,.............|
00000010  01 10 02 00 00 00 00 00  00 00 01 50 00 00 01 34  |...........P...4|
00000020  00 00 00 01 00 00 00 01  00 00 01 28 01 01 00 08  |...........(....|
00000030  03 00 00 24 01 01 00 00  80 01 00 05 80 02 00 02  |...$............|
00000040  80 03 00 01 80 04 00 02  80 0b 00 01 00 0c 00 04  |................|
00000050  00 00 70 80 03 00 00 24  02 01 00 00 80 01 00 05  |..p....$........|
00000060  80 02 00 01 80 03 00 01  80 04 00 02 80 0b 00 01  |................|
00000070  00 0c 00 04 00 00 70 80  03 00 00 24 03 01 00 00  |......p....$....|
00000080  80 01 00 01 80 02 00 02  80 03 00 01 80 04 00 02  |................|
00000090  80 0b 00 01 00 0c 00 04  00 00 70 80 03 00 00 24  |..........p....$|
000000a0  04 01 00 00 80 01 00 01  80 02 00 01 80 03 00 01  |................|
000000b0  80 04 00 02 80 0b 00 01  00 0c 00 04 00 00 70 80  |..............p.|
000000c0  03 00 00 24 05 01 00 00  80 01 00 05 80 02 00 02  |...$............|
000000d0  80 03 00 01 80 04 00 01  80 0b 00 01 00 0c 00 04  |................|
000000e0  00 00 70 80 03 00 00 24  06 01 00 00 80 01 00 05  |..p....$........|
000000f0  80 02 00 01 80 03 00 01  80 04 00 01 80 0b 00 01  |................|

Peer-to-peer

1 datagrams from 1 source

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp +3561628 to 54
SNMPv2161/udp15156.3
NTP123/udp319556.9
mDNS5353/udp662 to 10
NetBIOS137/udp +1553.8
SSDP1900/udp +15530.8
TFTP69/udp2260
RIPv1520/udp11131.24
CharGEN19/udp11358.8
WS-Discovery3702/udp1110 to 500

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
216.180.246.141AS396982 Google LLCUSDNS172026-10-10 11:12
216.180.246.101AS396982 Google LLCUSDNS172026-10-10 11:02
216.180.246.214AS396982 Google LLCUSDNS92026-10-10 16:32
34.22.219.27AS396982 Google LLCBENTP82026-10-11 08:35
35.233.53.61AS396982 Google LLCBENTP82026-10-11 08:45
35.187.115.138AS396982 Google LLCBENTP72026-10-11 08:47
216.25.89.125AS396982 Google LLCUSNTP42026-10-11 04:54
198.235.24.222AS396982 Google LLCUSUnrecognised32026-10-10 15:02
147.185.132.40AS396982 Google LLCUSUnrecognised32026-10-11 03:40
198.235.24.48AS396982 Google LLCUSDTLS32026-10-10 17:26
147.185.132.198AS396982 Google LLCUSSNMP32026-10-11 04:12
147.185.132.103AS396982 Google LLCUSSNMP22026-10-10 18:43
216.25.89.101AS396982 Google LLCUSUnrecognised22026-10-10 17:23
198.235.24.252AS396982 Google LLCUSUnrecognised22026-10-11 00:01
198.235.24.97AS396982 Google LLCUSDTLS22026-10-10 23:30
216.25.89.108AS396982 Google LLCUSUnrecognised22026-10-11 04:58
205.210.31.96AS396982 Google LLCUSUnrecognised22026-10-10 22:37
147.185.132.112AS396982 Google LLCUSDTLS22026-10-10 18:13
198.235.24.185AS396982 Google LLCUSSIP22026-10-11 03:00
205.210.31.59AS396982 Google LLCUSDTLS22026-10-11 08:02

Latest datagrams