HoneyLabs

UDP traffic

Datagrams matching asn:53006 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

28

Datagrams

4

Source addresses

1

Networks

1

Countries

5

Destination ports

Traffic by type

Service queries

24 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest SNMP datagram, to 161/udp

0&·Admin·a·0·0 ·+·+·

payload bytes
00000000  30 26 02 01 00 04 05 41  64 6d 69 6e a1 1a 02 04  |0&.....Admin....|
00000010  0e 94 a9 61 02 01 00 02  01 00 30 0c 30 0a 06 06  |...a......0.0...|
00000020  2b 06 01 02 01 2b 05 00                           |+....+..|

Other services

2 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SOCKS5 datagram, to 17323/udp

·4Vx·

payload bytes
00000000  05 00 ff ff 00 fe fe fe  fe fd fd fd fd 12 34 56  |..............4V|
00000010  78 0b 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |x...............|
00000020  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000030  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000040  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000050  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000060  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000070  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000080  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000a0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000b0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000c0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000d0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000e0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000f0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|

Unrecognised

2 datagrams from 2 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 65413/udp

zk·+p·=]S`ڎ·6C(_·ͱ·)·S·:·z2·g(Ec·<·[·4·;·á`· ·^·Ն*·!j ·

payload bytes
00000000  7a 6b cb 2b 70 a3 be 3d  5d 53 60 da 8e 96 36 43  |zk.+p..=]S`...6C|
00000010  28 5f e7 cd b1 b3 ee ab  29 ba 1b f1 bb 53 92 3a  |(_......)....S.:|
00000020  1c db 7a 32 f4 aa 91 1e  0b 90 67 28 45 63 95 3c  |..z2......g(Ec.<|
00000030  fd 5b c7 34 e2 a8 3b f1  a2 f2 c3 a1 60 06 09 1e  |.[.4..;.....`...|
00000040  15 5e ed ad d5 86 2a 85  89 21 6a 0d 1b 8b f8 01  |.^....*..!j.....|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SNMPv2161/udp2416.3

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
179.104.42.192AS53006 ALGAR TELECOM S/ABRSNMP242026-10-09 12:02
177.191.51.46AS53006 ALGAR TELECOM S/ABRSOCKS522026-10-07 22:05
177.191.20.33AS53006 ALGAR TELECOM S/ABRUnrecognised12026-10-08 19:15
189.15.246.140AS53006 ALGAR TELECOM S/ABRUnrecognised12026-10-08 13:12

Latest datagrams