HoneyLabs

UDP traffic

Datagrams matching country:DE sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

676

Datagrams

89

Source addresses

19

Networks

1

Countries

229

Destination ports

Traffic by type

Service queries

141 datagrams from 23 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

DNS query ANY dhitc.com

payload bytes
00000000  12 71 01 00 00 01 00 00  00 00 00 01 05 64 68 69  |.q...........dhi|
00000010  74 63 03 63 6f 6d 00 00  ff 00 01 00 00 29 ff ff  |tc.com.......)..|
00000020  00 00 00 00 00 00                                 |......|

Other services

113 datagrams from 19 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest Redis datagram, to 8082/udp

$.I·X$·K·%·3}q·{QG·}=t$T·z`t~·/G·k·S·

payload bytes
00000000  24 2e 49 02 58 24 07 4b  06 25 17 0e 33 7d 71 02  |$.I.X$.K.%..3}q.|
00000010  7b 51 47 11 19 7d 3d 74  24 54 19 7a 60 74 7e 04  |{QG..}=t$T.z`t~.|
00000020  2f 47 07 08 6b 0e 53 1c  0c                       |/G..k.S..|

QUIC

8 datagrams from 2 sources

Initial packets of HTTP/3 connections, decoded on the sensor.

Latest QUIC datagram, to 443/udp

QUIC v1 Initial alpn=h3,h3-29

Unrecognised

411 datagrams from 58 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 5060/udp

c.TvM;Ckc+·/H·+6·K%mN=QNg/_OEJ2·(OYk:<·Ul_f·f0`·.In}0·\·c&1dDZ3·EnZ\CF;*]·r

payload bytes
00000000  63 2e 54 76 4d 3b 43 6b  63 2b 1b 2f 48 11 2b 36  |c.TvM;Ckc+./H.+6|
00000010  00 18 4b 25 6d 4e 3d 51  4e 67 2f 5f 4f 45 4a 32  |..K%mN=QNg/_OEJ2|
00000020  01 1e 28 4f 59 6b 3a 3c  17 55 6c 5f 66 17 15 66  |..(OYk:<.Ul_f..f|
00000030  30 60 0b 1d 2e 49 6e 7d  30 1d 5c 7f 63 26 31 64  |0`...In}0.\.c&1d|
00000040  44 5a 33 1d 45 6e 5a 5c  43 46 3b 2a 5d 9a 72     |DZ3.EnZ\CF;*].r|

Peer-to-peer

3 datagrams from 3 sources

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp +1691028 to 54
mDNS5353/udp862 to 10
SNMPv2161/udp946.3
NTP123/udp84556.9
NetBIOS137/udp1933.8
SSDP1900/udp4330.8
WS-Discovery3702/udp28210 to 500
CLDAP389/udp26256 to 70
TFTP69/udp +16260

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

QUIC clients (JA4)

QUIC transport parameters

QUIC versions

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
46.101.133.66AS14061 DigitalOcean, LLCDEUnrecognised1352026-10-10 20:31
45.135.193.115AS51396 Pfcloud UG (haftungsbeschrankt)DEUnrecognised762026-10-11 03:59
185.73.23.133AS29484 Ruhr-Universitaet BochumDEDNS602026-10-10 09:32
141.82.3.32AS680 Verein zur Foerderung eines Deutschen FoDEUnrecognised232026-10-10 22:33
201.79.2.46AS14061 DigitalOcean, LLCDEUnrecognised212026-10-05 16:48
87.159.30.86AS3320 Deutsche Telekom AGDEUnrecognised202026-10-09 21:33
64.226.83.235AS14061 DigitalOcean, LLCDEUnrecognised182026-10-10 22:04
89.163.146.51AS24961 WIIT AGDERedis172026-10-05 17:40
89.163.239.201AS24961 WIIT AGDERedis162026-10-05 16:27
89.163.212.86AS24961 WIIT AGDERedis162026-10-05 16:28
193.111.198.244AS24961 WIIT AGDERedis162026-10-05 16:28
193.111.198.241AS24961 WIIT AGDERedis162026-10-05 16:27
104.248.129.131AS14061 DigitalOcean, LLCDEUnrecognised142026-10-05 16:14
165.154.164.21AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITDENetBIOS132026-10-08 08:08
176.65.134.60AS51396 Pfcloud UG (haftungsbeschrankt)DEDNS122026-10-09 17:01
201.79.14.100AS14061 DigitalOcean, LLCDEUnrecognised112026-10-08 15:41
31.70.64.154AS8560 IONOS SEDESIP102026-10-11 03:03
45.135.193.194AS51396 Pfcloud UG (haftungsbeschrankt)DEDNS92026-10-11 00:15
172.104.152.125AS63949 Akamai Connected CloudDEUnrecognised82026-10-10 10:52
179.254.163.155AS213877 U1 Digital Services LtdDEUnrecognised72026-10-10 22:02

Latest datagrams