UDP traffic
Datagrams matching asn:6939 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
1.1K
Datagrams
583
Source addresses
1
Networks
1
Countries
52
Destination ports
Traffic by type
Service queries
269 datagrams from 230 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 fa ce 01 00 00 01 00 00 00 00 00 00 07 64 6e 73 |.............dns| 00000010 73 63 61 6e 0c 73 68 61 64 6f 77 73 65 72 76 65 |scan.shadowserve| 00000020 72 03 6f 72 67 00 00 01 00 01 |r.org.....|
Other services
259 datagrams from 199 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest DTLS datagram, to 12646/udp
payload bytes
00000000 16 fe ff 00 00 00 00 00 00 00 00 00 36 01 00 00 |............6...| 00000010 2a 00 00 00 00 00 00 00 2a fe fd 00 00 00 00 7c |*.......*......|| 00000020 77 40 1e 8a c8 22 a0 a0 18 ff 93 08 ca ac 0a 64 |w@...".........d| 00000030 2f c9 22 64 bc 08 a8 16 89 19 30 00 00 00 02 00 |/."d......0.....| 00000040 2f 01 00 |/..|
Unrecognised
599 datagrams from 394 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 47808/udp
payload bytes
00000000 81 0a 00 11 01 04 00 05 e1 0c 0c 02 3f ff ff 19 |............?...| 00000010 4b |K|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| NTP | 123/udp | 37 | 36 | 556.9 |
| Memcached | 11211/udp +1 | 38 | 35 | 10,000 to 51,000 |
| DNS | 53/udp +1 | 25 | 23 | 28 to 54 |
| Portmap | 111/udp | 23 | 22 | 7 to 28 |
| NetBIOS | 137/udp | 23 | 22 | 3.8 |
| TFTP | 69/udp | 23 | 22 | 60 |
| QOTD | 17/udp | 21 | 21 | 140.3 |
| SNMPv2 | 161/udp | 21 | 20 | 6.3 |
| mDNS | 5353/udp | 20 | 20 | 2 to 10 |
| CLDAP | 389/udp | 20 | 20 | 56 to 70 |
| WS-Discovery | 3702/udp | 20 | 20 | 10 to 500 |
| CharGEN | 19/udp | 20 | 19 | 358.8 |
| SSDP | 1900/udp | 19 | 19 | 30.8 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
DNS questions
DNS record types
Networks
- AS6939 Hurricane Electric LLC from 583 sources1,127
Countries
- US United States1,127
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 216.218.142.110 | AS6939 Hurricane Electric LLC | US | TEREDO | 12 | 2026-10-07 20:34 |
| 65.49.1.63 | AS6939 Hurricane Electric LLC | US | Unrecognised | 7 | 2026-10-10 07:30 |
| 64.62.156.73 | AS6939 Hurricane Electric LLC | US | Unrecognised | 7 | 2026-10-10 08:31 |
| 64.62.156.22 | AS6939 Hurricane Electric LLC | US | GTP-C | 6 | 2026-10-10 08:01 |
| 65.49.1.10 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 06:38 |
| 65.49.1.70 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 02:37 |
| 65.49.1.72 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 08:39 |
| 64.62.156.17 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 02:42 |
| 64.62.156.53 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 03:04 |
| 64.62.156.72 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 06:14 |
| 184.105.247.247 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 02:47 |
| 65.49.1.117 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 01:28 |
| 65.49.1.36 | AS6939 Hurricane Electric LLC | US | DNS | 6 | 2026-10-11 02:39 |
| 65.49.1.54 | AS6939 Hurricane Electric LLC | US | SNMP | 6 | 2026-10-11 02:32 |
| 64.62.156.78 | AS6939 Hurricane Electric LLC | US | DNS | 5 | 2026-10-09 03:48 |
| 65.49.1.208 | AS6939 Hurricane Electric LLC | US | DTLS | 5 | 2026-10-08 08:16 |
| 64.62.197.194 | AS6939 Hurricane Electric LLC | US | Unrecognised | 5 | 2026-10-09 08:04 |
| 65.49.1.118 | AS6939 Hurricane Electric LLC | US | GTP-U | 5 | 2026-10-10 06:32 |
| 65.49.1.62 | AS6939 Hurricane Electric LLC | US | Unrecognised | 5 | 2026-10-10 08:48 |
| 64.62.156.83 | AS6939 Hurricane Electric LLC | US | Unrecognised | 5 | 2026-10-11 00:34 |
Latest datagrams
payload bytes
00000000 32 01 00 04 00 00 00 00 00 00 00 00 |2...........|
payload bytes
00000000 81 0a 00 11 01 04 00 05 e1 0c 0c 02 3f ff ff 19 |............?...| 00000010 4b |K|
payload bytes
00000000 30 53 02 01 01 04 06 70 75 62 6c 69 63 a0 46 02 |0S.....public.F.| 00000010 04 37 30 2e b3 02 01 00 02 01 00 30 38 30 0c 06 |.70........080..| 00000020 08 2b 06 01 02 01 01 01 00 05 00 30 0c 06 08 2b |.+.........0...+| 00000030 06 01 02 01 01 03 00 05 00 30 0c 06 08 2b 06 01 |.........0...+..| 00000040 02 01 04 03 00 05 00 30 0c 06 08 2b 06 01 02 01 |.......0...+....| 00000050 04 0a 00 05 00 |.....|
payload bytes
00000000 44 42 32 47 45 54 41 44 44 52 00 53 51 4c 30 39 |DB2GETADDR.SQL09| 00000010 30 31 30 00 |010.|
payload bytes
00000000 00 00 82 80 08 a7 3f 14 9d 2e 19 11 00 00 00 00 |......?.........| 00000010 00 00 00 00 0b 10 05 00 a3 1b f2 db 00 00 00 30 |...............0| 00000020 00 00 00 14 00 00 00 01 03 04 00 0b 00 00 82 80 |................| 00000030 00 00 82 80 |....|
payload bytes
00000000 0a |.|
payload bytes
00000000 32 01 00 04 00 00 00 00 00 00 00 00 |2...........|
payload bytes
00000000 00 01 00 02 00 01 00 |.......|
payload bytes
00000000 73 68 61 64 6f 77 73 65 72 76 65 72 20 65 63 68 |shadowserver ech| 00000010 6f 20 74 65 73 74 0a |o test.|
payload bytes
00000000 06 10 02 01 00 0e 08 01 40 3e 9c c4 84 c9 |........@>....|
payload bytes
00000000 4d 2d 53 45 41 52 43 48 20 2a 20 48 54 54 50 2f |M-SEARCH * HTTP/| 00000010 31 2e 31 0d 0a 48 6f 73 74 3a 32 33 39 2e 32 35 |1.1..Host:239.25| 00000020 35 2e 32 35 35 2e 32 35 30 3a 31 39 30 30 0d 0a |5.255.250:1900..| 00000030 53 54 3a 75 70 6e 70 3a 72 6f 6f 74 64 65 76 69 |ST:upnp:rootdevi| 00000040 63 65 0d 0a 4d 61 6e 3a 22 73 73 64 70 3a 64 69 |ce..Man:"ssdp:di| 00000050 73 63 6f 76 65 72 22 0d 0a 4d 58 3a 33 0d 0a 0d |scover"..MX:3...| 00000060 0a |.|
payload bytes
00000000 38 f6 00 00 00 01 00 00 00 00 00 00 20 43 4b 41 |8........... CKA| 00000010 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 |AAAAAAAAAAAAAAAA| 00000020 41 41 41 41 41 41 41 41 41 41 41 41 41 00 00 21 |AAAAAAAAAAAAA..!| 00000030 00 01 |..|
payload bytes
00000000 17 00 03 2a 00 00 00 00 00 00 00 00 |...*........|
payload bytes
00000000 16 fe ff 00 00 00 00 00 00 00 00 00 36 01 00 00 |............6...| 00000010 2a 00 00 00 00 00 00 00 2a fe fd 00 00 00 00 7c |*.......*......|| 00000020 77 40 1e 8a c8 22 a0 a0 18 ff 93 08 ca ac 0a 64 |w@...".........d| 00000030 2f c9 22 64 bc 08 a8 16 89 19 30 00 00 00 02 00 |/."d......0.....| 00000040 2f 01 00 |/..|
payload bytes
00000000 38 f6 00 00 00 01 00 00 00 00 00 00 20 43 4b 41 |8........... CKA| 00000010 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 |AAAAAAAAAAAAAAAA| 00000020 41 41 41 41 41 41 41 41 41 41 41 41 41 00 00 21 |AAAAAAAAAAAAA..!| 00000030 00 01 |..|