HoneyLabs

UDP traffic

Datagrams matching country:FR sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

481

Datagrams

109

Source addresses

14

Networks

1

Countries

152

Destination ports

Traffic by type

Service queries

112 datagrams from 25 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest SNMP datagram, to 161/udp

0)·public·N%·b·0·0·+·

payload bytes
00000000  30 29 02 01 00 04 06 70  75 62 6c 69 63 a0 1c 02  |0).....public...|
00000010  04 4e 25 86 62 02 01 00  02 01 00 30 0e 30 0c 06  |.N%.b......0.0..|
00000020  08 2b 06 01 02 01 01 01  00 05 00                 |.+.........|

Other services

108 datagrams from 47 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

REGISTER sip:chinamobile.com SIP/2.0 Via: SIP/2.0/UDP 51.178.198.251:4040;branch=z9hG4bK123 Max-Forwards: 70 From: <sip:me@chinamobile.com>;tag=12563 To: <sip:me@chinamobile.com> Call-ID: 3nPj9eWOvFlpMHn CSeq: 1 REGISTER Contact: <sip:me@51.178.198.251:4040> Expires: 3600 Allow: INVITE, ACK

payload bytes
00000000  52 45 47 49 53 54 45 52  20 73 69 70 3a 63 68 69  |REGISTER sip:chi|
00000010  6e 61 6d 6f 62 69 6c 65  2e 63 6f 6d 20 53 49 50  |namobile.com SIP|
00000020  2f 32 2e 30 0d 0a 56 69  61 3a 20 53 49 50 2f 32  |/2.0..Via: SIP/2|
00000030  2e 30 2f 55 44 50 20 35  31 2e 31 37 38 2e 31 39  |.0/UDP 51.178.19|
00000040  38 2e 32 35 31 3a 34 30  34 30 3b 62 72 61 6e 63  |8.251:4040;branc|
00000050  68 3d 7a 39 68 47 34 62  4b 31 32 33 0d 0a 4d 61  |h=z9hG4bK123..Ma|
00000060  78 2d 46 6f 72 77 61 72  64 73 3a 20 37 30 0d 0a  |x-Forwards: 70..|
00000070  46 72 6f 6d 3a 20 3c 73  69 70 3a 6d 65 40 63 68  |From: <sip:me@ch|
00000080  69 6e 61 6d 6f 62 69 6c  65 2e 63 6f 6d 3e 3b 74  |inamobile.com>;t|
00000090  61 67 3d 31 32 35 36 33  0d 0a 54 6f 3a 20 3c 73  |ag=12563..To: <s|
000000a0  69 70 3a 6d 65 40 63 68  69 6e 61 6d 6f 62 69 6c  |ip:me@chinamobil|
000000b0  65 2e 63 6f 6d 3e 0d 0a  43 61 6c 6c 2d 49 44 3a  |e.com>..Call-ID:|
000000c0  20 33 6e 50 6a 39 65 57  4f 76 46 6c 70 4d 48 6e  | 3nPj9eWOvFlpMHn|
000000d0  0d 0a 43 53 65 71 3a 20  31 20 52 45 47 49 53 54  |..CSeq: 1 REGIST|
000000e0  45 52 0d 0a 43 6f 6e 74  61 63 74 3a 20 3c 73 69  |ER..Contact: <si|
000000f0  70 3a 6d 65 40 35 31 2e  31 37 38 2e 31 39 38 2e  |p:me@51.178.198.|

Unrecognised

255 datagrams from 76 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 8082/udp

·.[b·K5T·1u·U4·^+·VNr,N z ·Tcda}·,2VCcKZ8·l·+omza·Hn·Ro'Zq·

payload bytes
00000000  00 2e 5b 62 0c 1a 1e 4b  35 54 17 31 75 17 55 34  |..[b...K5T.1u.U4|
00000010  11 5e 2b 03 56 4e 72 2c  4e 0d 7a 09 01 14 08 01  |.^+.VNr,N.z.....|
00000020  54 63 64 61 7d 02 2c 32  56 43 63 4b 5a 38 00 6c  |Tcda}.,2VCcKZ8.l|
00000030  17 2b 6f 6d 7a 61 19 48  6e 13 52 6f 27 5a 71 12  |.+omza.Hn.Ro'Zq.|
00000040  d3                                                |.|

Peer-to-peer

6 datagrams from 4 sources

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
SNMPv2161/udp4176.3
mDNS5353/udp1072 to 10
Memcached11211/udp11610,000 to 51,000
SSDP1900/udp6530.8
NetBIOS137/udp2743.8
DNS53/udp20428 to 54
NTP123/udp44556.9
Portmap111/udp437 to 28
WS-Discovery3702/udp4310 to 500
CLDAP389/udp3356 to 70
RIPv1520/udp22131.24

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
217.71.127.125AS198545 Flex Network SarlFRUnrecognised352026-10-10 23:27
62.210.89.150AS12876 Scaleway SASFRUnrecognised352026-10-11 04:06
62.210.90.215AS12876 Scaleway SASFRNetBIOS232026-10-11 00:37
62.210.142.176AS12876 Scaleway SASFRDNS172026-10-10 16:28
62.210.142.61AS12876 Scaleway SASFRSNMP172026-10-08 17:39
5.39.125.103AS16276 OVH SASFRSIP132026-10-10 22:40
91.231.89.92AS213412 ONYPHE SASFRUnrecognised122026-10-10 20:03
91.231.89.89AS213412 ONYPHE SASFRUnrecognised112026-10-10 20:06
91.231.89.91AS213412 ONYPHE SASFRUnrecognised112026-10-11 00:28
91.231.89.166AS213412 ONYPHE SASFRUnrecognised112026-10-10 09:39
91.231.89.88AS213412 ONYPHE SASFRUnrecognised102026-10-10 16:37
91.231.89.93AS213412 ONYPHE SASFRUnrecognised102026-10-10 23:33
91.231.89.160AS213412 ONYPHE SASFRDCE/RPC102026-10-10 23:49
91.231.89.90AS213412 ONYPHE SASFRUnrecognised102026-10-10 23:36
91.231.89.164AS213412 ONYPHE SASFRUnrecognised92026-10-10 02:40
91.231.89.165AS213412 ONYPHE SASFRUnrecognised92026-10-10 06:09
91.231.89.167AS213412 ONYPHE SASFRUnrecognised92026-10-10 13:08
91.231.89.94AS213412 ONYPHE SASFRUnrecognised82026-10-09 05:44
91.231.89.162AS213412 ONYPHE SASFRUnrecognised82026-10-09 19:41
91.231.89.95AS213412 ONYPHE SASFRUnrecognised82026-10-09 09:13

Latest datagrams