UDP traffic
Datagrams matching asn:63949 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
347
Datagrams
53
Source addresses
1
Networks
6
Countries
52
Destination ports
Traffic by type
Service queries
82 datagrams from 19 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 80 0a 01 00 00 01 00 00 00 00 00 00 06 69 6e 61 |.............ina| 00000010 6e 69 73 10 61 73 65 72 74 64 6e 73 72 65 73 65 |nis.asertdnsrese| 00000020 61 72 63 68 03 63 6f 6d 00 00 01 00 01 |arch.com.....|
Other services
20 datagrams from 6 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest SIP datagram, to 5060/udp
Payload bytes withheld: they contain the sensor's address.
Unrecognised
241 datagrams from 36 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 27021/udp
payload bytes
00000000 ff ff ff ff 54 53 6f 75 72 63 65 20 45 6e 67 69 |....TSource Engi| 00000010 6e 65 20 51 75 65 72 79 00 |ne Query.|
Peer-to-peer
4 datagrams from 1 sourceFile-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| DNS | 53/udp +1 | 19 | 5 | 28 to 54 |
| CLDAP | 389/udp | 7 | 4 | 56 to 70 |
| NTP | 123/udp | 15 | 3 | 556.9 |
| NetBIOS | 137/udp | 6 | 3 | 3.8 |
| TFTP | 6969/udp +1 | 8 | 2 | 60 |
| SNMPv2 | 161/udp | 8 | 2 | 6.3 |
| SSDP | 1900/udp | 5 | 2 | 30.8 |
| Memcached | 11211/udp | 5 | 2 | 10,000 to 51,000 |
| Portmap | 111/udp | 4 | 2 | 7 to 28 |
| mDNS | 5353/udp | 4 | 2 | 2 to 10 |
| RIPv1 | 520/udp | 4 | 1 | 131.24 |
| CharGEN | 19/udp | 4 | 1 | 358.8 |
| QOTD | 17/udp | 4 | 1 | 140.3 |
| WS-Discovery | 3702/udp | 4 | 1 | 10 to 500 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
DNS questions
DNS record types
Networks
- AS63949 Akamai Connected Cloud from 53 sources347
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 139.162.88.198 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 52 | 2026-10-10 19:24 |
| 139.162.116.160 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 48 | 2026-10-11 01:55 |
| 139.162.120.104 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 16 | 2026-10-10 20:10 |
| 139.162.66.65 | AS63949 Akamai Connected Cloud | JP | DNS | 10 | 2026-10-10 18:01 |
| 66.228.41.127 | AS63949 Akamai Connected Cloud | US | Unrecognised | 9 | 2026-10-06 20:58 |
| 139.162.109.245 | AS63949 Akamai Connected Cloud | JP | NTP | 8 | 2026-10-09 15:37 |
| 66.175.212.77 | AS63949 Akamai Connected Cloud | US | SIP | 8 | 2026-10-07 00:01 |
| 139.162.113.92 | AS63949 Akamai Connected Cloud | JP | NTP | 8 | 2026-10-10 18:42 |
| 45.33.73.73 | AS63949 Akamai Connected Cloud | US | SIP | 8 | 2026-10-07 15:19 |
| 172.105.101.33 | AS63949 Akamai Connected Cloud | CA | Unrecognised | 8 | 2026-10-10 07:29 |
| 172.104.152.125 | AS63949 Akamai Connected Cloud | DE | Unrecognised | 8 | 2026-10-10 10:52 |
| 96.126.114.244 | AS63949 Akamai Connected Cloud | US | Unrecognised | 7 | 2026-10-09 15:46 |
| 45.79.190.10 | AS63949 Akamai Connected Cloud | US | Unrecognised | 6 | 2026-10-06 17:58 |
| 45.33.46.249 | AS63949 Akamai Connected Cloud | US | HTTP | 5 | 2026-10-10 15:41 |
| 66.228.53.221 | AS63949 Akamai Connected Cloud | US | Unrecognised | 4 | 2026-10-11 01:58 |
| 139.162.116.104 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 4 | 2026-10-05 19:11 |
| 172.105.13.33 | AS63949 Akamai Connected Cloud | CA | SSDP | 4 | 2026-10-07 18:59 |
| 170.187.181.208 | AS63949 Akamai Connected Cloud | CA | Unrecognised | 4 | 2026-10-08 02:15 |
| 139.162.165.197 | AS63949 Akamai Connected Cloud | DE | Unrecognised | 4 | 2026-10-09 12:57 |
| 139.162.159.191 | AS63949 Akamai Connected Cloud | DE | TFTP | 4 | 2026-10-08 08:48 |
Latest datagrams
payload bytes
00000000 ff ff ff ff 54 53 6f 75 72 63 65 20 45 6e 67 69 |....TSource Engi| 00000010 6e 65 20 51 75 65 72 79 00 |ne Query.|
payload bytes
00000000 41 41 41 41 41 41 41 41 6e 65 74 63 6f 72 65 00 |AAAAAAAAnetcore.| 00000010 0a |.|
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 41 41 41 41 41 41 41 41 6e 65 74 63 6f 72 65 00 |AAAAAAAAnetcore.| 00000010 0a |.|
payload bytes
00000000 63 61 6c 6c 2e 73 74 61 72 74 62 6c 61 73 74 20 |call.startblast | 00000010 32 30 30 30 20 33 0a |2000 3.|
payload bytes
00000000 41 41 41 41 41 41 41 41 6e 65 74 63 6f 72 65 00 |AAAAAAAAnetcore.| 00000010 0a |.|
payload bytes
00000000 63 61 6c 6c 2e 73 74 61 72 74 62 6c 61 73 74 20 |call.startblast | 00000010 32 30 30 30 20 33 0a |2000 3.|
payload bytes
00000000 41 41 41 41 41 41 41 41 6e 65 74 63 6f 72 65 00 |AAAAAAAAnetcore.| 00000010 0a |.|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 ff ff ff ff 54 53 6f 75 72 63 65 20 45 6e 67 69 |....TSource Engi| 00000010 6e 65 20 51 75 65 72 79 00 |ne Query.|
payload bytes
00000000 38 12 12 12 12 12 12 12 12 00 00 00 00 00 38 b1 |8.............8.| 00000010 26 de |&.|
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 38 00 00 00 00 00 00 00 00 00 00 00 01 |8............|
payload bytes
00000000 38 00 00 00 00 00 00 00 00 00 00 00 01 |8............|