HoneyLabs

UDP traffic

Datagrams matching country:GB sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

572

Datagrams

289

Source addresses

16

Networks

1

Countries

163

Destination ports

Traffic by type

Service queries

91 datagrams from 64 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest Sun RPC datagram, to 2049/udp

C·qn·

payload bytes
00000000  43 ec 71 6e 00 00 00 00  00 00 00 02 00 01 86 a0  |C.qn............|
00000010  00 00 00 04 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000020  00 00 00 00 00 00 00 00                           |........|

Other services

160 datagrams from 56 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

INVITE sip:100@<HONEYPOT> SIP/2.0 Via: SIP/2.0/UDP 127.0.0.1:5218;branch=z9hG4bK-1330281108;rport Content-Length: 0 From: "sipvicious"<sip:100@1.1.1.1>;tag=6239653435316339313363340131373036333435393434 Accept: application/sdp User-Agent: friendly-scanner To: "sipvicious"<sip:100@1.1.1.1> Con

Payload bytes withheld: they contain the sensor's address.

QUIC

99 datagrams from 86 sources

Initial packets of HTTP/3 connections, decoded on the sensor.

Latest QUIC datagram, to 443/udp

QUIC v1 Initial alpn=http/0.9,http/1.0,spdy/1,spdy/2,spdy/3,stun.turn,stun.nat-discovery,h2c,webrtc,c-webrtc,ftp,imap,pop3,managesieve,coap,co

Unrecognised

221 datagrams from 137 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 1027/udp

s.G·-ncl_·:88p'N·'GH·+_(2 4·

payload bytes
00000000  73 2e 47 10 2d 6e 63 6c  5f 10 3a 38 38 70 27 4e  |s.G.-ncl_.:88p'N|
00000010  0e 27 47 48 08 17 06 2b  5f 28 32 0d 34 f9        |.'GH...+_(2.4.|

Peer-to-peer

1 datagrams from 1 source

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp +3171728 to 54
SNMPv2161/udp15156.3
NTP123/udp108556.9
SSDP1900/udp +310830.8
Portmap111/udp977 to 28
NetBIOS2137/udp +3553.8
WS-Discovery3702/udp8310 to 500
mDNS5353/udp222 to 10
TFTP19876/udp +12260
RIPv1520/udp41131.24
Memcached11211/udp1110,000 to 51,000

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

QUIC clients (JA4)

QUIC transport parameters

QUIC versions

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
198.244.200.163AS16276 OVH SASGBSIP702026-10-11 03:05
185.200.118.46AS9009 M247 Europe SRLGBGOOGLE232026-10-10 22:30
167.71.143.137AS14061 DigitalOcean, LLCGBUnrecognised82026-10-07 14:06
8.208.10.94AS45102 Alibaba (US) Technology Co., Ltd.GBQUIC72026-10-10 02:37
165.227.238.235AS14061 DigitalOcean, LLCGBUnrecognised72026-10-11 02:59
86.25.66.22AS5089 Virgin MediaGBUnrecognised62026-10-08 00:28
193.163.125.139AS211298 Driftnet LtdGBUnrecognised62026-10-10 22:23
193.163.125.170AS211298 Driftnet LtdGBUnrecognised52026-10-10 22:56
193.163.125.173AS211298 Driftnet LtdGBSNMP52026-10-11 02:48
193.163.125.241AS211298 Driftnet LtdGBSOAP52026-10-08 22:52
193.163.125.116AS211298 Driftnet LtdGBUnrecognised52026-10-09 03:09
193.163.125.178AS211298 Driftnet LtdGBDTLS52026-10-10 17:59
193.163.125.130AS211298 Driftnet LtdGBDNS42026-10-10 23:43
178.79.137.171AS63949 Akamai Connected CloudGBUnrecognised42026-10-07 13:25
212.71.250.62AS63949 Akamai Connected CloudGBUnrecognised42026-10-07 01:38
193.163.125.231AS211298 Driftnet LtdGBUnrecognised42026-10-11 02:36
193.163.125.137AS211298 Driftnet LtdGBUnrecognised42026-10-10 14:10
193.163.125.175AS211298 Driftnet LtdGBUnrecognised42026-10-08 09:32
178.79.148.203AS63949 Akamai Connected CloudGBUnrecognised42026-10-09 14:21
193.163.125.150AS211298 Driftnet LtdGBDNS42026-10-09 10:35

Latest datagrams