HoneyLabs

UDP traffic

Datagrams matching country:CN sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

64

Datagrams

33

Source addresses

9

Networks

1

Countries

29

Destination ports

Traffic by type

Other services

5 datagrams from 5 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

OPTIONS sip:nm SIP/2.0 Via: SIP/2.0/UDP nm;branch=foo;rport Max-Forwards: 70 To: <sip:nm@nm> From: <sip:nm@nm>;tag=root Call-ID: 50000 CSeq: 63104 OPTIONS Contact: <sip:nm@nm> Accept: application/sdp Content-Length: 0

payload bytes
00000000  4f 50 54 49 4f 4e 53 20  73 69 70 3a 6e 6d 20 53  |OPTIONS sip:nm S|
00000010  49 50 2f 32 2e 30 0d 0a  56 69 61 3a 20 53 49 50  |IP/2.0..Via: SIP|
00000020  2f 32 2e 30 2f 55 44 50  20 6e 6d 3b 62 72 61 6e  |/2.0/UDP nm;bran|
00000030  63 68 3d 66 6f 6f 3b 72  70 6f 72 74 0d 0a 4d 61  |ch=foo;rport..Ma|
00000040  78 2d 46 6f 72 77 61 72  64 73 3a 20 37 30 0d 0a  |x-Forwards: 70..|
00000050  54 6f 3a 20 3c 73 69 70  3a 6e 6d 40 6e 6d 3e 0d  |To: <sip:nm@nm>.|
00000060  0a 46 72 6f 6d 3a 20 3c  73 69 70 3a 6e 6d 40 6e  |.From: <sip:nm@n|
00000070  6d 3e 3b 74 61 67 3d 72  6f 6f 74 0d 0a 43 61 6c  |m>;tag=root..Cal|
00000080  6c 2d 49 44 3a 20 35 30  30 30 30 0d 0a 43 53 65  |l-ID: 50000..CSe|
00000090  71 3a 20 36 33 31 30 34  20 4f 50 54 49 4f 4e 53  |q: 63104 OPTIONS|
000000a0  0d 0a 43 6f 6e 74 61 63  74 3a 20 3c 73 69 70 3a  |..Contact: <sip:|
000000b0  6e 6d 40 6e 6d 3e 0d 0a  41 63 63 65 70 74 3a 20  |nm@nm>..Accept: |
000000c0  61 70 70 6c 69 63 61 74  69 6f 6e 2f 73 64 70 0d  |application/sdp.|
000000d0  0a 43 6f 6e 74 65 6e 74  2d 4c 65 6e 67 74 68 3a  |.Content-Length:|
000000e0  20 30 0d 0a 0d 0a                                 | 0....|

Unrecognised

33 datagrams from 26 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 31065/udp

·&NT^·TY{·4Vx3·̅Kg&·

payload bytes
00000000  01 26 4e 54 5e da 54 59  7b 00 ff ff 00 fe fe fe  |.&NT^.TY{.......|
00000010  fe fd fd fd fd 12 34 56  78 33 de cc 85 4b 67 26  |......4Vx3...Kg&|
00000020  d9                                                |.|

Peer-to-peer

26 datagrams from 2 sources

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
mDNS5353/udp222 to 10
RIPv1520/udp11131.24

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
218.16.197.7AS140308 CHINATELECOM Guangdong province Zhuhai 5CNBitTorrent152026-10-10 08:53
223.157.171.209AS4134 ChinanetCNBitTorrent112026-10-10 08:52
103.203.57.10AS136180 Beijing Tiantexin Tech. Co., Ltd.CNUnrecognised42026-10-10 23:42
122.246.8.150AS136188 NINGBO, ZHEJIANG Province, P.R.China.CNUnrecognised22026-10-11 03:01
103.203.57.27AS136180 Beijing Tiantexin Tech. Co., Ltd.CNUnrecognised22026-10-11 03:42
106.75.176.152AS58466 CHINANET Guangdong province networkCNUnrecognised22026-10-10 21:17
103.203.57.24AS136180 Beijing Tiantexin Tech. Co., Ltd.CNUnrecognised22026-10-10 18:33
59.49.230.168AS4134 ChinanetCNUnrecognised12026-10-10 11:17
106.117.111.115AS4134 ChinanetCNUnrecognised12026-10-10 11:16
122.136.26.139AS4837 CHINA UNICOM China169 BackboneCNSOCKS512026-10-10 13:10
116.30.9.218AS4134 ChinanetCNUnrecognised12026-10-11 01:28
123.144.21.9AS4837 CHINA UNICOM China169 BackboneCNUnrecognised12026-10-10 22:27
139.170.73.194AS4837 CHINA UNICOM China169 BackboneCNUnrecognised12026-10-10 06:28
113.206.146.178AS4837 CHINA UNICOM China169 BackboneCNUnrecognised12026-10-10 17:06
183.250.25.11AS9808 China Mobile Communications Group Co., LCNUnrecognised12026-10-10 07:37
125.84.251.37AS4134 ChinanetCNSIP12026-10-10 06:50
124.31.106.10AS4134 ChinanetCNSIP12026-10-10 19:01
139.202.232.10AS4134 ChinanetCNUnrecognised12026-10-10 09:02
60.16.213.143AS4837 CHINA UNICOM China169 BackboneCNUnrecognised12026-10-10 08:53
183.129.101.37AS4134 ChinanetCNUnrecognised12026-10-10 08:00

Latest datagrams