HoneyLabs

UDP traffic

Datagrams matching country:DE sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

133

Datagrams

27

Source addresses

12

Networks

1

Countries

92

Destination ports

Traffic by type

Service queries

19 datagrams from 5 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

DNS query ANY dhitc.com

payload bytes
00000000  12 71 01 00 00 01 00 00  00 00 00 01 05 64 68 69  |.q...........dhi|
00000010  74 63 03 63 6f 6d 00 00  ff 00 01 00 00 29 ff ff  |tc.com.......)..|
00000020  00 00 00 00 00 00                                 |......|

Other services

4 datagrams from 3 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

OPTIONS sip:100@<HONEYPOT> SIP/2.0 Via: SIP/2.0/UDP 31.70.64.154:5069;branch=z9hG4bK-3517743053;rport Max-Forwards: 70 To: "sipvicious"<sip:100@1.1.1.1> From: "sipvicious"<sip:100@1.1.1.1>;tag=6330303337363932313363340133353736303835363235 User-Agent: friendly-scanner Call-ID: 9103947926586866

Payload bytes withheld: they contain the sensor's address.

Unrecognised

110 datagrams from 22 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 5060/udp

c.TvM;Ckc+·/H·+6·K%mN=QNg/_OEJ2·(OYk:<·Ul_f·f0`·.In}0·\·c&1dDZ3·EnZ\CF;*]·r

payload bytes
00000000  63 2e 54 76 4d 3b 43 6b  63 2b 1b 2f 48 11 2b 36  |c.TvM;Ckc+./H.+6|
00000010  00 18 4b 25 6d 4e 3d 51  4e 67 2f 5f 4f 45 4a 32  |..K%mN=QNg/_OEJ2|
00000020  01 1e 28 4f 59 6b 3a 3c  17 55 6c 5f 66 17 15 66  |..(OYk:<.Ul_f..f|
00000030  30 60 0b 1d 2e 49 6e 7d  30 1d 5c 7f 63 26 31 64  |0`...In}0.\.c&1d|
00000040  44 5a 33 1d 45 6e 5a 5c  43 46 3b 2a 5d 9a 72     |DZ3.EnZ\CF;*].r|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp15528 to 54
CLDAP389/udp4156 to 70
WS-Discovery3702/udp4110 to 500
mDNS5353/udp112 to 10

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
46.101.133.66AS14061 DigitalOcean, LLCDEUnrecognised672026-10-10 20:31
45.135.193.115AS51396 Pfcloud UG (haftungsbeschrankt)DEUnrecognised142026-10-11 03:59
185.73.23.133AS29484 Ruhr-Universitaet BochumDEDNS122026-10-10 09:32
64.226.83.235AS14061 DigitalOcean, LLCDEUnrecognised62026-10-10 22:04
141.82.3.32AS680 Verein zur Foerderung eines Deutschen FoDEUnrecognised42026-10-10 22:33
45.135.193.194AS51396 Pfcloud UG (haftungsbeschrankt)DEDNS32026-10-11 00:15
207.241.172.146AS206216 Advin Services LLCDEUnrecognised32026-10-11 02:43
139.162.186.195AS63949 Akamai Connected CloudDEUnrecognised32026-10-10 21:54
179.254.163.155AS213877 U1 Digital Services LtdDEUnrecognised22026-10-10 22:02
31.70.64.154AS8560 IONOS SEDESIP22026-10-11 03:03
217.160.190.176AS8560 IONOS SEDEUnrecognised12026-10-11 03:55
45.82.78.100AS212512 Detai Prosperous Technologies LimitedDESIP12026-10-10 23:42
172.104.152.125AS63949 Akamai Connected CloudDEUnrecognised12026-10-10 10:52
8.211.42.24AS45102 Alibaba (US) Technology Co., Ltd.DEUnrecognised12026-10-11 01:57
164.92.182.157AS14061 DigitalOcean, LLCDEDNS12026-10-10 06:42
87.150.15.111AS3320 Deutsche Telekom AGDEUnrecognised12026-10-10 06:08
47.245.141.134AS45102 Alibaba (US) Technology Co., Ltd.DEUnrecognised12026-10-10 13:00
8.211.44.115AS45102 Alibaba (US) Technology Co., Ltd.DEUnrecognised12026-10-11 01:45
8.209.83.9AS45102 Alibaba (US) Technology Co., Ltd.DEUnrecognised12026-10-11 03:55
91.34.37.59AS3320 Deutsche Telekom AGDEUnrecognised12026-10-11 04:21

Latest datagrams