UDP traffic
Datagrams matching asn:6939 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
1.3K
Datagrams
617
Source addresses
1
Networks
1
Countries
52
Destination ports
Traffic by type
Service queries
302 datagrams from 251 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 5353/udp
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
Other services
288 datagrams from 217 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest DTLS datagram, to 12346/udp
payload bytes
00000000 16 fe ff 00 00 00 00 00 00 00 00 00 36 01 00 00 |............6...| 00000010 2a 00 00 00 00 00 00 00 2a fe fd 00 00 00 00 7c |*.......*......|| 00000020 77 40 1e 8a c8 22 a0 a0 18 ff 93 08 ca ac 0a 64 |w@...".........d| 00000030 2f c9 22 64 bc 08 a8 16 89 19 30 00 00 00 02 00 |/."d......0.....| 00000040 2f 01 00 |/..|
Unrecognised
670 datagrams from 424 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 2123/udp
payload bytes
00000000 40 01 00 04 00 00 00 00 00 00 00 00 |@...........|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| Memcached | 11211/udp +1 | 44 | 41 | 10,000 to 51,000 |
| NTP | 123/udp | 41 | 40 | 556.9 |
| DNS | 53/udp +1 | 28 | 26 | 28 to 54 |
| CLDAP | 389/udp | 24 | 24 | 56 to 70 |
| WS-Discovery | 3702/udp | 24 | 24 | 10 to 500 |
| mDNS | 5353/udp | 24 | 23 | 2 to 10 |
| TFTP | 69/udp | 24 | 23 | 60 |
| QOTD | 17/udp | 23 | 23 | 140.3 |
| SNMPv2 | 161/udp | 24 | 22 | 6.3 |
| Portmap | 111/udp | 23 | 22 | 7 to 28 |
| NetBIOS | 137/udp | 23 | 22 | 3.8 |
| CharGEN | 19/udp | 23 | 22 | 358.8 |
| SSDP | 1900/udp | 22 | 22 | 30.8 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
DNS questions
DNS record types
Networks
- AS6939 Hurricane Electric LLC from 617 sources1,260
Countries
- US United States1,260
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 216.218.142.110 | AS6939 Hurricane Electric LLC | US | TEREDO | 12 | 2026-10-07 20:34 |
| 64.62.156.53 | AS6939 Hurricane Electric LLC | US | Unrecognised | 8 | 2026-10-11 06:58 |
| 64.62.156.22 | AS6939 Hurricane Electric LLC | US | Unrecognised | 7 | 2026-10-11 06:33 |
| 65.49.1.63 | AS6939 Hurricane Electric LLC | US | Unrecognised | 7 | 2026-10-10 07:30 |
| 65.49.1.70 | AS6939 Hurricane Electric LLC | US | Unrecognised | 7 | 2026-10-11 04:24 |
| 64.62.156.73 | AS6939 Hurricane Electric LLC | US | Unrecognised | 7 | 2026-10-10 08:31 |
| 65.49.1.36 | AS6939 Hurricane Electric LLC | US | CLDAP | 7 | 2026-10-11 05:57 |
| 65.49.1.10 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 06:38 |
| 65.49.1.208 | AS6939 Hurricane Electric LLC | US | DTLS | 6 | 2026-10-11 06:30 |
| 65.49.1.72 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 08:39 |
| 64.62.156.17 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 02:42 |
| 65.49.1.52 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 05:54 |
| 64.62.156.72 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 06:14 |
| 184.105.247.247 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-10 02:47 |
| 65.49.1.117 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 01:28 |
| 65.49.1.54 | AS6939 Hurricane Electric LLC | US | Unrecognised | 6 | 2026-10-11 02:32 |
| 64.62.156.78 | AS6939 Hurricane Electric LLC | US | Unrecognised | 5 | 2026-10-09 03:48 |
| 64.62.197.194 | AS6939 Hurricane Electric LLC | US | Unrecognised | 5 | 2026-10-09 08:04 |
| 65.49.1.112 | AS6939 Hurricane Electric LLC | US | Unrecognised | 5 | 2026-10-11 07:24 |
| 65.49.1.118 | AS6939 Hurricane Electric LLC | US | SNMP | 5 | 2026-10-10 06:32 |
Latest datagrams
payload bytes
00000000 73 74 61 74 73 0a |stats.|
payload bytes
00000000 40 01 00 04 00 00 00 00 00 00 00 00 |@...........|
payload bytes
00000000 3a 3c 3e 2f 0a |:<>/.|
payload bytes
00000000 4f 50 54 49 4f 4e 53 |OPTIONS|
payload bytes
00000000 32 01 00 04 00 00 00 00 00 00 00 00 |2...........|
payload bytes
00000000 e4 7a 59 1f 78 c9 9d 7f a0 0b 8e f0 ea 9f f8 83 |.zY.x...........| 00000010 08 10 20 01 e2 2a 74 c1 00 00 00 3c 76 9e 59 d6 |.. ..*t....<v.Y.| 00000020 f8 55 3e 22 99 1a 4d b1 cd 29 ca d8 77 c6 5c 33 |.U>"..M..)..w.\3| 00000030 27 39 f1 06 a2 bf 6f 1d 2f 5b f5 2e |'9....o./[..|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 0a |.|
payload bytes
00000000 00 00 82 80 08 a7 3f 14 9d 2e 19 11 00 00 00 00 |......?.........| 00000010 00 00 00 00 0b 10 05 00 a3 1b f2 db 00 00 00 30 |...............0| 00000020 00 00 00 14 00 00 00 01 03 04 00 0b 00 00 82 80 |................| 00000030 00 00 82 80 |....|
payload bytes
00000000 0a |.|
payload bytes
00000000 00 00 00 00 00 01 00 00 73 74 61 74 73 0a |........stats.|
payload bytes
00000000 16 fe ff 00 00 00 00 00 00 00 00 00 36 01 00 00 |............6...| 00000010 2a 00 00 00 00 00 00 00 2a fe fd 00 00 00 00 7c |*.......*......|| 00000020 77 40 1e 8a c8 22 a0 a0 18 ff 93 08 ca ac 0a 64 |w@...".........d| 00000030 2f c9 22 64 bc 08 a8 16 89 19 30 00 00 00 02 00 |/."d......0.....| 00000040 2f 01 00 |/..|
payload bytes
00000000 66 a1 e3 6d 49 ec ea 20 00 00 00 00 00 00 00 00 |f..mI.. ........| 00000010 21 20 22 08 00 00 00 00 00 00 02 24 22 00 00 30 |! "........$"..0| 00000020 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c |...,............| 00000030 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 |................| 00000040 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 |............(...| 00000050 00 0e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000080 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000090 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| ... 512 bytes shown in part
payload bytes
00000000 4d 2d 53 45 41 52 43 48 20 2a 20 48 54 54 50 2f |M-SEARCH * HTTP/| 00000010 31 2e 31 0d 0a 48 6f 73 74 3a 32 33 39 2e 32 35 |1.1..Host:239.25| 00000020 35 2e 32 35 35 2e 32 35 30 3a 31 39 30 30 0d 0a |5.255.250:1900..| 00000030 53 54 3a 75 70 6e 70 3a 72 6f 6f 74 64 65 76 69 |ST:upnp:rootdevi| 00000040 63 65 0d 0a 4d 61 6e 3a 22 73 73 64 70 3a 64 69 |ce..Man:"ssdp:di| 00000050 73 63 6f 76 65 72 22 0d 0a 4d 58 3a 33 0d 0a 0d |scover"..MX:3...| 00000060 0a |.|
payload bytes
00000000 80 00 02 00 00 00 00 63 00 ef 05 01 00 |.......c.....|