HoneyLabs

UDP traffic

Datagrams matching asn:6939 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

213

Datagrams

187

Source addresses

1

Networks

1

Countries

51

Destination ports

Traffic by type

Service queries

46 datagrams from 43 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 5353/udp

DNS query PTR _services._dns-sd._udp.local

payload bytes
00000000  00 00 00 00 00 01 00 00  00 00 00 00 09 5f 73 65  |............._se|
00000010  72 76 69 63 65 73 07 5f  64 6e 73 2d 73 64 04 5f  |rvices._dns-sd._|
00000020  75 64 70 05 6c 6f 63 61  6c 00 00 0c 00 01        |udp.local.....|

Other services

46 datagrams from 46 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest DTLS datagram, to 13046/udp

·6·*·*·|w@·"·ʬ d/·"d·0·/·

payload bytes
00000000  16 fe ff 00 00 00 00 00  00 00 00 00 36 01 00 00  |............6...|
00000010  2a 00 00 00 00 00 00 00  2a fe fd 00 00 00 00 7c  |*.......*......||
00000020  77 40 1e 8a c8 22 a0 a0  18 ff 93 08 ca ac 0a 64  |w@...".........d|
00000030  2f c9 22 64 bc 08 a8 16  89 19 30 00 00 00 02 00  |/."d......0.....|
00000040  2f 01 00                                          |/..|

Unrecognised

121 datagrams from 112 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 32414/udp

M

payload bytes
00000000  4d                                                |M|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
NTP123/udp88556.9
Memcached11211/udp +17710,000 to 51,000
Portmap111/udp767 to 28
TFTP69/udp6560
DNS53/udp5528 to 54
QOTD17/udp55140.3
mDNS5353/udp442 to 10
SSDP1900/udp4430.8
NetBIOS137/udp333.8
CLDAP389/udp3356 to 70
CharGEN19/udp33358.8
WS-Discovery3702/udp3310 to 500
SNMPv2161/udp226.3

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
64.62.156.32AS6939 Hurricane Electric LLCUSGTP-C42026-10-11 04:22
65.49.1.117AS6939 Hurricane Electric LLCUSUnrecognised32026-10-11 01:28
64.62.197.88AS6939 Hurricane Electric LLCUSTFTP32026-10-10 08:10
64.62.197.39AS6939 Hurricane Electric LLCUSDNS22026-10-11 02:14
65.49.1.70AS6939 Hurricane Electric LLCUSUnrecognised22026-10-11 04:24
65.49.1.85AS6939 Hurricane Electric LLCUSUnrecognised22026-10-10 14:48
64.62.156.161AS6939 Hurricane Electric LLCUSDTLS22026-10-11 03:31
64.62.197.140AS6939 Hurricane Electric LLCUSUnrecognised22026-10-11 03:29
184.105.247.243AS6939 Hurricane Electric LLCUSUnrecognised22026-10-11 02:56
65.49.1.89AS6939 Hurricane Electric LLCUSSun RPC22026-10-11 01:14
184.105.247.235AS6939 Hurricane Electric LLCUSDNS22026-10-11 02:02
64.62.156.80AS6939 Hurricane Electric LLCUSUnrecognised22026-10-10 07:53
65.49.1.210AS6939 Hurricane Electric LLCUSSSDP22026-10-11 02:02
65.49.20.106AS6939 Hurricane Electric LLCUSNTP22026-10-11 01:36
65.49.1.36AS6939 Hurricane Electric LLCUSNetBIOS22026-10-11 02:39
64.62.197.112AS6939 Hurricane Electric LLCUSUnrecognised22026-10-10 07:11
64.62.156.10AS6939 Hurricane Electric LLCUSUnrecognised22026-10-11 03:52
64.62.197.121AS6939 Hurricane Electric LLCUSXDMCP22026-10-11 02:14
64.62.156.83AS6939 Hurricane Electric LLCUSUnrecognised22026-10-11 00:34
64.62.156.129AS6939 Hurricane Electric LLCUSUnrecognised22026-10-11 03:33

Latest datagrams