HoneyLabs

UDP traffic

Datagrams matching asn:4766 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

36

Datagrams

16

Source addresses

1

Networks

1

Countries

18

Destination ports

Traffic by type

Service queries

12 datagrams from 12 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest NTP datagram, to 123/udp

·

payload bytes
00000000  1c 00 00 00                                       |....|

Unrecognised

24 datagrams from 4 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 26850/udp

·@·6j3YM·C·Bttf/_·a·vJB·s·ɔ·S·Bl·(~Њ·ZKg^_·)·{·x·@+!·j·Y·B·ø@{·|Dd`·T ·Wm؃;[z·N·"·=f ·$U·R)·}· ·=·f·{]jg·Mj·>·pd·X*·u·r·

payload bytes
00000000  85 b7 40 d2 36 6a 33 59  4d 07 ac 43 f2 42 74 74  |..@.6j3YM..C.Btt|
00000010  66 2f 5f a3 e1 83 ff 61  fc 76 4a 42 95 cf ff 94  |f/_....a.vJB....|
00000020  73 e6 81 ce c9 94 fc 53  dc f5 10 42 6c 19 f9 28  |s......S...Bl..(|
00000030  7e d0 8a e9 5a 4b 67 5e  5f eb 1c 9b 29 b3 ce 7b  |~...ZKg^_...)..{|
00000040  0e 95 78 c4 40 2b 21 a0  08 6a 1b dc 59 dd 42 d2  |..x.@+!..j..Y.B.|
00000050  fa f2 92 d2 c3 b8 40 7b  89 d6 0c 7c 44 64 60 b8  |......@{...|Dd`.|
00000060  90 54 20 fd 57 6d d8 83  3b 5b 7a 99 14 4e 83 22  |.T .Wm..;[z..N."|
00000070  00 1a f8 dd 3d 66 0a 9d  24 55 e2 d6 02 52 29 ee  |....=f..$U...R).|
00000080  dd 7d 1c f3 0d d6 e9 3d  e1 ef 66 f9 8d 0b 7b 5d  |.}.....=..f...{]|
00000090  6a 67 99 4d 6a 89 b3 3e  ba 70 64 f0 58 2a c6 75  |jg.Mj..>.pd.X*.u|
000000a0  bd b1 e2 f3 72 8e b8 51  5f c5 8a 82 bc ab 5a c6  |....r..Q_.....Z.|
000000b0  93 85 d3 20 e5 54 8d b5  36 df f9 61 fe 9f ed 72  |... .T..6..a...r|
000000c0  2d 73 ae ce 61 3c 5b 11  13 51 f4 be 5c 3b f8 a0  |-s..a<[..Q..\;..|
000000d0  75 03 72 1d 8e 8c 02 d5  f4 23 62 c9 5f c3 21 a8  |u.r......#b._.!.|
000000e0  85 14 c5 25 4f 8a 62 e4  b4 68 c7 3c 48 6f 5a 9a  |...%O.b..h.<HoZ.|
000000f0  ba 21 36 97 e1 f1 f6 67  63 b7 73 60 0a b4 1a 29  |.!6....gc.s`...)|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
NTP123/udp1212556.9

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
14.39.180.249AS4766 Korea TelecomKRUnrecognised172026-10-11 04:26
221.164.137.248AS4766 Korea TelecomKRUnrecognised42026-10-10 11:28
211.217.108.4AS4766 Korea TelecomKRUnrecognised22026-10-10 14:43
59.25.45.164AS4766 Korea TelecomKRNTP12026-10-10 15:24
14.56.250.242AS4766 Korea TelecomKRNTP12026-10-10 20:39
218.157.41.201AS4766 Korea TelecomKRUnrecognised12026-10-10 19:23
14.44.66.3AS4766 Korea TelecomKRNTP12026-10-10 11:04
14.45.214.121AS4766 Korea TelecomKRNTP12026-10-10 12:42
14.49.145.150AS4766 Korea TelecomKRNTP12026-10-10 14:37
14.32.83.9AS4766 Korea TelecomKRNTP12026-10-10 02:21
14.49.174.230AS4766 Korea TelecomKRNTP12026-10-10 14:36
14.48.253.6AS4766 Korea TelecomKRNTP12026-10-10 14:49
14.51.20.89AS4766 Korea TelecomKRNTP12026-10-10 16:15
14.42.178.201AS4766 Korea TelecomKRNTP12026-10-10 09:28
14.45.162.29AS4766 Korea TelecomKRNTP12026-10-10 11:41
14.50.165.253AS4766 Korea TelecomKRNTP12026-10-10 15:20

Latest datagrams