UDP traffic
Datagrams matching country:DE sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Your plan searches up to 7d, so 30d was shortened. Plans
675
Datagrams
88
Source addresses
19
Networks
1
Countries
229
Destination ports
Traffic by type
Service queries
141 datagrams from 23 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|
Other services
113 datagrams from 19 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest Redis datagram, to 8082/udp
payload bytes
00000000 24 2e 49 02 58 24 07 4b 06 25 17 0e 33 7d 71 02 |$.I.X$.K.%..3}q.|
00000010 7b 51 47 11 19 7d 3d 74 24 54 19 7a 60 74 7e 04 |{QG..}=t$T.z`t~.|
00000020 2f 47 07 08 6b 0e 53 1c 0c |/G..k.S..|QUIC
8 datagrams from 2 sourcesInitial packets of HTTP/3 connections, decoded on the sensor.
Latest QUIC datagram, to 443/udp
Unrecognised
410 datagrams from 57 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 3702/udp
payload bytes
00000000 3c 3a 3e |<:>|
Peer-to-peer
3 datagrams from 3 sourcesFile-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| DNS | 53/udp +1 | 69 | 10 | 28 to 54 |
| mDNS | 5353/udp | 8 | 6 | 2 to 10 |
| SNMPv2 | 161/udp | 9 | 4 | 6.3 |
| NTP | 123/udp | 8 | 4 | 556.9 |
| NetBIOS | 137/udp | 19 | 3 | 3.8 |
| SSDP | 1900/udp | 4 | 3 | 30.8 |
| WS-Discovery | 3702/udp | 28 | 2 | 10 to 500 |
| CLDAP | 389/udp | 26 | 2 | 56 to 70 |
| TFTP | 69/udp +1 | 6 | 2 | 60 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
DNS questions
DNS record types
QUIC clients (JA4)
- q13i0310h3_55b375c5d22e_df5b9e597968 from 1 source4
QUIC transport parameters
- 94dccb934778 from 1 source4
QUIC versions
Networks
- AS14061 DigitalOcean, LLC from 15 sources211
- AS51396 Pfcloud UG (haftungsbeschrankt) from 3 sources97
- AS24961 WIIT AG from 5 sources81
- AS29484 Ruhr-Universitaet Bochum from 1 source60
- AS45102 Alibaba (US) Technology Co., Ltd. from 26 sources48
- AS3320 Deutsche Telekom AG from 7 sources37
- AS63949 Akamai Connected Cloud from 9 sources35
- AS680 Verein zur Foerderung eines Deutschen Fo from 2 sources27
- AS8560 IONOS SE from 5 sources25
- AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT from 1 source13
Countries
- DE Germany675
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 46.101.133.66 | AS14061 DigitalOcean, LLC | DE | Unrecognised | 135 | 2026-10-10 20:31 |
| 45.135.193.115 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | Unrecognised | 76 | 2026-10-11 03:59 |
| 185.73.23.133 | AS29484 Ruhr-Universitaet Bochum | DE | DNS | 60 | 2026-10-10 09:32 |
| 141.82.3.32 | AS680 Verein zur Foerderung eines Deutschen Fo | DE | Unrecognised | 23 | 2026-10-10 22:33 |
| 201.79.2.46 | AS14061 DigitalOcean, LLC | DE | Unrecognised | 21 | 2026-10-05 16:48 |
| 87.159.30.86 | AS3320 Deutsche Telekom AG | DE | Unrecognised | 20 | 2026-10-09 21:33 |
| 64.226.83.235 | AS14061 DigitalOcean, LLC | DE | Unrecognised | 18 | 2026-10-10 22:04 |
| 89.163.146.51 | AS24961 WIIT AG | DE | Redis | 17 | 2026-10-05 17:40 |
| 89.163.212.86 | AS24961 WIIT AG | DE | Redis | 16 | 2026-10-05 16:28 |
| 193.111.198.244 | AS24961 WIIT AG | DE | Redis | 16 | 2026-10-05 16:28 |
| 193.111.198.241 | AS24961 WIIT AG | DE | Redis | 16 | 2026-10-05 16:27 |
| 89.163.239.201 | AS24961 WIIT AG | DE | Redis | 16 | 2026-10-05 16:27 |
| 104.248.129.131 | AS14061 DigitalOcean, LLC | DE | Unrecognised | 14 | 2026-10-05 16:14 |
| 165.154.164.21 | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT | DE | NetBIOS | 13 | 2026-10-08 08:08 |
| 176.65.134.60 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | DNS | 12 | 2026-10-09 17:01 |
| 201.79.14.100 | AS14061 DigitalOcean, LLC | DE | Unrecognised | 11 | 2026-10-08 15:41 |
| 31.70.64.154 | AS8560 IONOS SE | DE | SIP | 10 | 2026-10-11 03:03 |
| 45.135.193.194 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | DNS | 9 | 2026-10-11 00:15 |
| 172.104.152.125 | AS63949 Akamai Connected Cloud | DE | Unrecognised | 8 | 2026-10-10 10:52 |
| 179.254.163.155 | AS213877 U1 Digital Services Ltd | DE | Unrecognised | 7 | 2026-10-10 22:02 |
Latest datagrams
payload bytes
00000000 3c 3a 3e |<:>|
payload bytes
00000000 78 2e 7e 21 50 21 45 3c 40 51 7b 18 19 73 6d 46 |x.~!P!E<@Q{..smF| 00000010 40 7c 28 21 79 30 60 34 1e 3f 52 54 4c 16 2a 44 |@|(!y0`4.?RTL.*D| 00000020 35 28 65 05 4a 2a 41 f0 1b |5(e.J*A..|payload bytes
00000000 01 00 00 00 00 01 00 0d 01 00 00 4e 20 |...........N |
payload bytes
00000000 06 00 ff 06 00 00 11 be 80 00 00 00 |............|
Payload bytes withheld: they contain the sensor's address.
Payload bytes withheld: they contain the sensor's address.
payload bytes
00000000 7b 2e 2b 0f 05 4b 55 76 4e 1b 70 33 0f 2f 41 60 |{.+..KUvN.p3./A`| 00000010 76 68 2f 76 03 3f 44 50 46 59 1d 59 26 0d 09 21 |vh/v.?DPFY.Y&..!| 00000020 67 34 31 6d 00 06 63 4e 21 53 01 31 02 42 11 78 |g41m..cN!S.1.B.x| 00000030 2a 40 6e 2e 7f 32 7e 45 0c 1b 1f 32 28 28 54 0f |*@n..2~E...2((T.| 00000040 5d 05 7c 5d 0b 60 2b 2c 33 2c 5d 36 6e 6e 2e 18 |].|].`+,3,]6nn..| 00000050 2e 1d 46 2e 4f 44 73 5b 5f 12 0e 07 3b 62 17 18 |..F.ODs[_...;b..| 00000060 67 24 82 |g$.|payload bytes
00000000 24 2e 49 02 58 24 07 4b 06 25 17 0e 33 7d 71 02 |$.I.X$.K.%..3}q.| 00000010 7b 51 47 11 19 7d 3d 74 24 54 19 7a 60 74 7e 04 |{QG..}=t$T.z`t~.| 00000020 2f 47 07 08 6b 0e 53 1c 0c |/G..k.S..|payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|
payload bytes
00000000 48 41 50 e6 01 6e 68 0d 00 1a 00 09 00 01 50 01 |HAP..nh.......P.| 00000010 02 00 01 00 17 52 |.....R|
payload bytes
00000000 00 00 00 00 61 62 63 64 65 66 67 68 |....abcdefgh|
payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|
payload bytes
00000000 45 67 01 00 00 01 00 00 00 00 00 01 02 75 75 02 |Eg...........uu.| 00000010 6e 6c 00 00 ff 00 01 00 00 29 ff ff 00 00 00 00 |nl.......)......| 00000020 00 00 |..|
payload bytes
00000000 4f 50 54 49 4f 4e 53 20 73 69 70 3a 6e 6d 20 53 |OPTIONS sip:nm S| 00000010 49 50 2f 32 2e 30 0d 0a 56 69 61 3a 20 53 49 50 |IP/2.0..Via: SIP| 00000020 2f 32 2e 30 2f 54 43 50 20 6e 6d 3b 62 72 61 6e |/2.0/TCP nm;bran| 00000030 63 68 3d 66 6f 6f 0d 0a 46 72 6f 6d 3a 20 3c 73 |ch=foo..From: <s| 00000040 69 70 3a 6e 6d 40 6e 6d 3e 3b 74 61 67 3d 72 6f |ip:nm@nm>;tag=ro| 00000050 6f 74 0d 0a 54 6f 3a 20 3c 73 69 70 3a 6e 6d 32 |ot..To: <sip:nm2| 00000060 40 6e 6d 32 3e 0d 0a 43 61 6c 6c 2d 49 44 3a 20 |@nm2>..Call-ID: | 00000070 35 30 30 30 30 0d 0a 43 53 65 71 3a 20 34 32 20 |50000..CSeq: 42 | 00000080 4f 50 54 49 4f 4e 53 0d 0a 4d 61 78 2d 46 6f 72 |OPTIONS..Max-For| 00000090 77 61 72 64 73 3a 20 37 30 0d 0a 43 6f 6e 74 65 |wards: 70..Conte| 000000a0 6e 74 2d 4c 65 6e 67 74 68 3a 20 30 0d 0a 43 6f |nt-Length: 0..Co| 000000b0 6e 74 61 63 74 3a 20 3c 73 69 70 3a 6e 6d 40 6e |ntact: <sip:nm@n| 000000c0 6d 3e 0d 0a 41 63 63 65 70 74 3a 20 61 70 70 6c |m>..Accept: appl| 000000d0 69 63 61 74 69 6f 6e 2f 73 64 70 0d 0a 0d 0a |ication/sdp....|
payload bytes
00000000 12 71 01 00 00 01 00 00 00 00 00 01 05 64 68 69 |.q...........dhi| 00000010 74 63 03 63 6f 6d 00 00 ff 00 01 00 00 29 ff ff |tc.com.......)..| 00000020 00 00 00 00 00 00 |......|