HoneyLabs

UDP traffic

Datagrams matching asn:8585 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

1

Datagrams

1

Source addresses

1

Networks

1

Countries

1

Destination ports

Traffic by type

Other services

1 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest Redis datagram, to 54385/udp

*·N·oNo·ߖ·-v ·ݤ3·jZ·U·@whW·= ·@+·Ll·jx·j]·Q·DA^!·$t[/^·E·{·$_Q·2· ·b,i·jE·۽·ǬYBL·B·Uf·E·=·8·2·+·E·ۑ>yj·'·I-ӵ·&/>q

payload bytes
00000000  2a ad 4e d0 f5 6f 4e 6f  a9 88 df 96 bb 2d 76 0a  |*.N..oNo.....-v.|
00000010  0e dd a4 33 f2 6a 5a cb  fa f0 55 01 a1 84 93 8c  |...3.jZ...U.....|
00000020  40 77 68 57 c5 3d 09 ba  e3 40 2b ce 4c 6c 87 11  |@whW.=...@+.Ll..|
00000030  cb 6a 78 ca 6a 5d e8 51  83 b2 cf 44 41 5e 21 8a  |.jx.j].Q...DA^!.|
00000040  9d 24 74 5b 2f 5e b6 01  13 15 ae 8f 45 89 e0 d8  |.$t[/^......E...|
00000050  0b cc 7b f1 ef 24 5f 51  01 d5 32 be 06 01 20 d4  |..{..$_Q..2... .|
00000060  d0 62 2c 69 c9 6a 45 15  d0 ff f1 db bd 8d 12 c7  |.b,i.jE.........|
00000070  ac 59 42 4c 93 42 b2 55  66 f5 d3 45 17 f5 e1 3d  |.YBL.B.Uf..E...=|
00000080  be b6 b6 c7 38 ff 13 d5  e6 15 32 bb 16 2b da dc  |....8.....2..+..|
00000090  45 8d db 91 3e 79 6a 0e  d4 cf f8 27 89 49 2d d3  |E...>yj....'.I-.|
000000a0  b5 8d 26 2f 3e 71 0f 71  ae 9e 5e 3f 0a 21 31     |..&/>q.q..^?.!1|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
77.222.7.253AS8585 Crnogorski Telekom a.d.PodgoricaMERedis12026-10-06 13:38

Latest datagrams