HoneyLabs

UDP traffic

Datagrams matching country:DE sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

671

Datagrams

86

Source addresses

19

Networks

1

Countries

228

Destination ports

Traffic by type

Service queries

141 datagrams from 23 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

DNS query ANY dhitc.com

payload bytes
00000000  12 71 01 00 00 01 00 00  00 00 00 01 05 64 68 69  |.q...........dhi|
00000010  74 63 03 63 6f 6d 00 00  ff 00 01 00 00 29 ff ff  |tc.com.......)..|
00000020  00 00 00 00 00 00                                 |......|

Other services

113 datagrams from 19 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest Redis datagram, to 8082/udp

$.I·X$·K·%·3}q·{QG·}=t$T·z`t~·/G·k·S·

payload bytes
00000000  24 2e 49 02 58 24 07 4b  06 25 17 0e 33 7d 71 02  |$.I.X$.K.%..3}q.|
00000010  7b 51 47 11 19 7d 3d 74  24 54 19 7a 60 74 7e 04  |{QG..}=t$T.z`t~.|
00000020  2f 47 07 08 6b 0e 53 1c  0c                       |/G..k.S..|

QUIC

8 datagrams from 2 sources

Initial packets of HTTP/3 connections, decoded on the sensor.

Latest QUIC datagram, to 443/udp

QUIC v1 Initial alpn=h3,h3-29

Unrecognised

406 datagrams from 55 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 1027/udp

{.+·KUvN·p3·/A`vh/v·?DPFY·Y& !g41m·cN!S·1·B·x*@n.·2~E·2((T·]·|]·`+,3,]6nn.·.·F.ODs[_·;b·g$·

payload bytes
00000000  7b 2e 2b 0f 05 4b 55 76  4e 1b 70 33 0f 2f 41 60  |{.+..KUvN.p3./A`|
00000010  76 68 2f 76 03 3f 44 50  46 59 1d 59 26 0d 09 21  |vh/v.?DPFY.Y&..!|
00000020  67 34 31 6d 00 06 63 4e  21 53 01 31 02 42 11 78  |g41m..cN!S.1.B.x|
00000030  2a 40 6e 2e 7f 32 7e 45  0c 1b 1f 32 28 28 54 0f  |*@n..2~E...2((T.|
00000040  5d 05 7c 5d 0b 60 2b 2c  33 2c 5d 36 6e 6e 2e 18  |].|].`+,3,]6nn..|
00000050  2e 1d 46 2e 4f 44 73 5b  5f 12 0e 07 3b 62 17 18  |..F.ODs[_...;b..|
00000060  67 24 82                                          |g$.|

Peer-to-peer

3 datagrams from 3 sources

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp +1691028 to 54
mDNS5353/udp862 to 10
SNMPv2161/udp946.3
NTP123/udp84556.9
NetBIOS137/udp1933.8
SSDP1900/udp4330.8
WS-Discovery3702/udp27210 to 500
CLDAP389/udp26256 to 70
TFTP69/udp +16260

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

QUIC clients (JA4)

QUIC transport parameters

QUIC versions

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
46.101.133.66AS14061 DigitalOcean, LLCDEUnrecognised1352026-10-10 20:31
45.135.193.115AS51396 Pfcloud UG (haftungsbeschrankt)DEUnrecognised752026-10-11 02:15
185.73.23.133AS29484 Ruhr-Universitaet BochumDECoAP602026-10-10 09:32
141.82.3.32AS680 Verein zur Foerderung eines Deutschen FoDEUnrecognised232026-10-10 22:33
201.79.2.46AS14061 DigitalOcean, LLCDEUnrecognised212026-10-05 16:48
87.159.30.86AS3320 Deutsche Telekom AGDEUnrecognised202026-10-09 21:33
64.226.83.235AS14061 DigitalOcean, LLCDEUnrecognised182026-10-10 22:04
89.163.146.51AS24961 WIIT AGDERedis172026-10-05 17:40
193.111.198.241AS24961 WIIT AGDERedis162026-10-05 16:27
89.163.212.86AS24961 WIIT AGDERedis162026-10-05 16:28
193.111.198.244AS24961 WIIT AGDERedis162026-10-05 16:28
89.163.239.201AS24961 WIIT AGDERedis162026-10-05 16:27
104.248.129.131AS14061 DigitalOcean, LLCDEUnrecognised142026-10-05 16:14
165.154.164.21AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITDENetBIOS132026-10-08 08:08
176.65.134.60AS51396 Pfcloud UG (haftungsbeschrankt)DECoAP122026-10-09 17:01
201.79.14.100AS14061 DigitalOcean, LLCDEUnrecognised112026-10-08 15:41
31.70.64.154AS8560 IONOS SEDESIP102026-10-11 03:03
45.135.193.194AS51396 Pfcloud UG (haftungsbeschrankt)DEDNS92026-10-11 00:15
172.104.152.125AS63949 Akamai Connected CloudDEUnrecognised82026-10-10 10:52
179.254.163.155AS213877 U1 Digital Services LtdDEUnrecognised72026-10-10 22:02

Latest datagrams