HoneyLabs

UDP traffic

Datagrams matching asn:51167 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

19

Datagrams

5

Source addresses

1

Networks

1

Countries

8

Destination ports

Traffic by type

Service queries

4 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest SNMP datagram, to 161/udp

0;·0·SNMP·0·0·0·

payload bytes
00000000  30 3b 02 01 03 30 11 02  04 53 4e 4d 50 02 03 00  |0;...0...SNMP...|
00000010  ff e3 04 01 04 02 01 03  04 10 30 0e 04 00 02 01  |..........0.....|
00000020  00 02 01 00 04 00 04 00  04 00 30 11 04 00 04 00  |..........0.....|
00000030  a0 0b 02 01 00 02 01 00  02 01 00 30 00           |...........0.|

Unrecognised

14 datagrams from 4 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 4000/udp

·.T=]ve·g·/W·>·Bh_w·yWM·1·;Q>7fY·#6·Qh·@·z

payload bytes
00000000  15 2e 54 3d 5d 76 65 1a  67 10 2f 57 12 3e 05 19  |..T=]ve.g./W.>..|
00000010  42 68 5f 77 18 79 57 4d  1a 31 02 3b 51 3e 37 66  |Bh_w.yWM.1.;Q>7f|
00000020  59 0b 23 36 01 08 51 68  18 00 40 e8 7a           |Y.#6..Qh..@.z|

Peer-to-peer

1 datagrams from 1 source

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SNMPv2161/udp416.3

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
169.58.136.173AS51167 Contabo GmbHFRUnrecognised62026-10-08 04:46
169.58.11.22AS51167 Contabo GmbHFRUnrecognised62026-10-10 08:23
161.97.174.218AS51167 Contabo GmbHFRSNMP42026-10-07 22:16
158.220.107.11AS51167 Contabo GmbHFRUnrecognised22026-10-06 10:51
217.76.50.205AS51167 Contabo GmbHFRUnrecognised12026-10-11 07:21

Latest datagrams