UDP traffic
Datagrams matching asn:44382 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
5
Datagrams
2
Source addresses
1
Networks
2
Countries
3
Destination ports
Traffic by type
Other services
4 datagrams from 1 sourceFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest SIP datagram, to 5060/udp
Payload bytes withheld: they contain the sensor's address.
Unrecognised
1 datagrams from 1 sourceDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 11211/udp
payload bytes
00000000 00 00 00 00 00 01 00 00 73 74 61 74 73 0d 0a |........stats..|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| Memcached | 11211/udp | 1 | 1 | 10,000 to 51,000 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 45.141.148.75 | AS44382 Fiba Cloud Operation Company, LLC | TR | SIP | 4 | 2026-10-10 03:56 |
| 216.9.225.228 | AS44382 Fiba Cloud Operation Company, LLC | US | Unrecognised | 1 | 2026-10-07 09:46 |
Latest datagrams
Payload bytes withheld: they contain the sensor's address.
Payload bytes withheld: they contain the sensor's address.
Payload bytes withheld: they contain the sensor's address.
payload bytes
00000000 00 00 00 00 00 01 00 00 73 74 61 74 73 0d 0a |........stats..|
Payload bytes withheld: they contain the sensor's address.