UDP traffic
Datagrams matching asn:51396 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Your plan searches up to 7d, so 30d was shortened. Plans
118
Datagrams
9
Source addresses
1
Networks
3
Countries
16
Destination ports
Traffic by type
Service queries
54 datagrams from 7 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|
Other services
1 datagrams from 1 sourceFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest Redis datagram, to 1604/udp
payload bytes
00000000 2a 00 01 32 02 fd a8 e3 00 00 00 00 00 00 00 00 |*..2............| 00000010 00 00 00 00 00 00 00 00 00 00 00 00 21 00 02 00 |............!...| 00000020 00 00 00 00 00 00 00 00 00 00 |..........|
Unrecognised
63 datagrams from 6 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 3702/udp
payload bytes
00000000 3c 3a 3e |<:>|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| DNS | 53/udp | 39 | 4 | 28 to 54 |
| CharGEN | 19/udp | 6 | 2 | 358.8 |
| SSDP | 1900/udp | 5 | 2 | 30.8 |
| WS-Discovery | 3702/udp | 26 | 1 | 10 to 500 |
| CLDAP | 389/udp | 25 | 1 | 56 to 70 |
| NTP | 123/udp | 2 | 1 | 556.9 |
| NetBIOS | 137/udp | 2 | 1 | 3.8 |
| SNMPv2 | 161/udp | 2 | 1 | 6.3 |
| mDNS | 5353/udp | 1 | 1 | 2 to 10 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
DNS questions
DNS record types
Networks
- AS51396 Pfcloud UG (haftungsbeschrankt) from 9 sources118
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 45.135.193.115 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | Unrecognised | 78 | 2026-10-11 06:44 |
| 176.65.134.60 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | CoAP | 12 | 2026-10-09 17:01 |
| 45.135.193.194 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | DNS | 9 | 2026-10-11 00:15 |
| 176.65.149.208 | AS51396 Pfcloud UG (haftungsbeschrankt) | NL | Unrecognised | 8 | 2026-10-11 03:28 |
| 176.65.149.188 | AS51396 Pfcloud UG (haftungsbeschrankt) | NL | Redis | 3 | 2026-10-11 06:39 |
| 94.183.174.99 | AS51396 Pfcloud UG (haftungsbeschrankt) | AE | Unrecognised | 3 | 2026-10-07 19:28 |
| 176.65.148.78 | AS51396 Pfcloud UG (haftungsbeschrankt) | NL | Unrecognised | 2 | 2026-10-11 06:10 |
| 176.65.149.233 | AS51396 Pfcloud UG (haftungsbeschrankt) | NL | Unrecognised | 2 | 2026-10-11 03:04 |
| 176.65.149.254 | AS51396 Pfcloud UG (haftungsbeschrankt) | NL | DNS | 1 | 2026-10-10 15:40 |
Latest datagrams
payload bytes
00000000 3c 3a 3e |<:>|
payload bytes
00000000 2a 00 01 32 02 fd a8 e3 00 00 00 00 00 00 00 00 |*..2............| 00000010 00 00 00 00 00 00 00 00 00 00 00 00 21 00 02 00 |............!...| 00000020 00 00 00 00 00 00 00 00 00 00 |..........|
payload bytes
00000000 3c 3a 3e |<:>|
payload bytes
00000000 40 01 7d 70 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.}p..well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 3c 3a 3e |<:>|
payload bytes
00000000 0a |.|
payload bytes
00000000 01 |.|
payload bytes
00000000 0a |.|
payload bytes
00000000 0a |.|
payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|
payload bytes
00000000 81 0a 00 11 01 04 00 05 d6 0c 0c 02 3f ff ff 19 |............?...| 00000010 4b 4c |KL|
payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|
payload bytes
00000000 45 67 01 00 00 01 00 00 00 00 00 01 02 75 75 02 |Eg...........uu.| 00000010 6e 6c 00 00 ff 00 01 00 00 29 ff ff 00 00 00 00 |nl.......)......| 00000020 00 00 |..|
payload bytes
00000000 00 14 00 00 |....|
payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|