HoneyLabs

UDP traffic

Datagrams matching country:CA sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

42

Datagrams

13

Source addresses

8

Networks

1

Countries

30

Destination ports

Traffic by type

Service queries

3 datagrams from 3 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest NTP datagram, to 123/udp

·O#Kq·R·

payload bytes
00000000  e3 00 04 fa 00 01 00 00  00 01 00 00 00 00 00 00  |................|
00000010  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000020  00 00 00 00 00 00 00 00  c5 4f 23 4b 71 b1 52 f3  |.........O#Kq.R.|

Other services

26 datagrams from 3 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 50007/udp

OPTIONS sip:100@<HONEYPOT> SIP/2.0 Via: SIP/2.0/UDP 51.161.57.3:7715;branch=z9hG4bK-4287440660;rport Content-Length: 0 From: "sipvicious"<sip:100@1.1.1.1>;tag=31373565323565336333353701363937373232363334 Accept: application/sdp User-Agent: friendly-scanner To: "sipvicious"<sip:100@1.1.1.1> Co

Payload bytes withheld: they contain the sensor's address.

Unrecognised

13 datagrams from 7 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 5060/udp

·.j2·wY·^·]7U iB·Fx?5·G;e·s3·Dv*Ra\aX6z6=Xn·eWTz·M9Rk· P·.EyY·Z5y2kti(LW:1·6

payload bytes
00000000  1b 2e 6a 32 0f 77 59 19  5e 07 5d 37 55 0d 69 42  |..j2.wY.^.]7U.iB|
00000010  14 46 78 3f 35 1e 47 3b  65 1f 73 33 0f 44 76 2a  |.Fx?5.G;e.s3.Dv*|
00000020  52 61 5c 61 58 36 7a 36  3d 58 6e 12 65 57 54 7a  |Ra\aX6z6=Xn.eWTz|
00000030  1d 4d 39 52 6b 00 0d 50  1f 01 03 2e 45 79 59 18  |.M9Rk..P....EyY.|
00000040  5a 35 79 32 6b 74 69 28  4c 57 3a 31 1a 36        |Z5y2kti(LW:1.6|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
mDNS5353/udp112 to 10
NTP123/udp11556.9
SNMPv2161/udp116.3
SSDP1900/udp1130.8
Memcached11211/udp1110,000 to 51,000
WS-Discovery3702/udp1110 to 500

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
51.161.57.3AS16276 OVH SASCASIP242026-10-10 14:23
174.138.216.234AS11814 Distributel Communications LimitedCAUnrecognised52026-10-11 04:41
2604:a880:cad:d0:0:1:ba2b:9001AS14061 DigitalOcean, LLCCAUnrecognised32026-10-10 22:18
85.217.149.24AS209334 Modat B.V.CAUnrecognised12026-10-10 05:31
86.54.31.34AS12989 Black HOST LtdCASNMP12026-10-10 16:20
172.105.101.33AS63949 Akamai Connected CloudCAUnrecognised12026-10-10 07:29
51.161.33.215AS16276 OVH SASCAUnrecognised12026-10-10 11:37
86.54.31.38AS12989 Black HOST LtdCASOAP12026-10-10 23:38
86.54.31.32AS12989 Black HOST LtdCANTP12026-10-10 05:50
66.222.149.159AS852 TELUS Communications Inc.CAUnrecognised12026-10-10 21:23
207.81.204.231AS852 TELUS Communications Inc.CASOCKS512026-10-10 15:33
99.233.136.193AS812 Rogers Communications Canada Inc.CASOCKS512026-10-10 13:05
99.250.196.13AS812 Rogers Communications Canada Inc.CAUnrecognised12026-10-10 13:29

Latest datagrams