HoneyLabs

UDP traffic

Datagrams matching asn:57043 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

3

Datagrams

1

Source addresses

1

Networks

1

Countries

3

Destination ports

Traffic by type

Unrecognised

3 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 1900/udp

·.0·q5o6pE>:|·.?· ;·#·[K·L·-(pL·!W·VF7F·u·|/G·<·`!w+:DA?qj/=zP·xH

payload bytes
00000000  1e 2e 30 0b 71 35 6f 36  70 45 3e 3a 7c 07 2e 3f  |..0.q5o6pE>:|..?|
00000010  1e 0d 3b 01 23 1e 5b 4b  19 4c 16 04 2d 28 70 4c  |..;.#.[K.L..-(pL|
00000020  10 21 57 01 56 46 37 46  0c 75 00 08 7c 2f 47 1b  |.!W.VF7F.u..|/G.|
00000030  3c 03 1c 60 21 77 2b 3a  44 41 3f 71 6a 2f 3d 7a  |<..`!w+:DA?qj/=z|
00000040  50 15 78 48                                       |P.xH|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SSDP1900/udp1130.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
141.11.209.245AS57043 Hostkey B.v.NLUnrecognised32026-10-11 08:46

Latest datagrams