HoneyLabs

UDP traffic

Datagrams matching country:GB sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

589

Datagrams

293

Source addresses

16

Networks

1

Countries

168

Destination ports

Traffic by type

Service queries

94 datagrams from 64 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest Sun RPC datagram, to 2049/udp

C·qn·

payload bytes
00000000  43 ec 71 6e 00 00 00 00  00 00 00 02 00 01 86 a0  |C.qn............|
00000010  00 00 00 04 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000020  00 00 00 00 00 00 00 00                           |........|

Other services

167 datagrams from 57 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

INVITE sip:100@<HONEYPOT> SIP/2.0 Via: SIP/2.0/UDP 127.0.0.1:5276;branch=z9hG4bK-3426049020;rport Content-Length: 0 From: "sipvicious"<sip:100@1.1.1.1>;tag=6239653435316339313363340133353435393434313337 Accept: application/sdp User-Agent: friendly-scanner To: "sipvicious"<sip:100@1.1.1.1> Con

Payload bytes withheld: they contain the sensor's address.

QUIC

99 datagrams from 86 sources

Initial packets of HTTP/3 connections, decoded on the sensor.

Latest QUIC datagram, to 443/udp

QUIC v1 Initial alpn=http/0.9,http/1.0,spdy/1,spdy/2,spdy/3,stun.turn,stun.nat-discovery,h2c,webrtc,c-webrtc,ftp,imap,pop3,managesieve,coap,co

Unrecognised

228 datagrams from 140 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 37700/udp

8f·6CK·y·

payload bytes
00000000  38 66 01 36 43 4b 81 af  79 00 00 00 00 00        |8f.6CK..y.....|

Peer-to-peer

1 datagrams from 1 source

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp +3171728 to 54
SNMPv2161/udp17166.3
NTP123/udp118556.9
SSDP1900/udp +310830.8
Portmap111/udp977 to 28
NetBIOS2137/udp +3553.8
WS-Discovery3702/udp8310 to 500
mDNS5353/udp222 to 10
TFTP19876/udp +12260
RIPv1520/udp41131.24
Memcached11211/udp1110,000 to 51,000

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

QUIC clients (JA4)

QUIC transport parameters

QUIC versions

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
198.244.200.163AS16276 OVH SASGBSIP752026-10-11 08:38
185.200.118.46AS9009 M247 Europe SRLGBGOOGLE232026-10-10 22:30
167.71.143.137AS14061 DigitalOcean, LLCGBUnrecognised82026-10-07 14:06
8.208.10.94AS45102 Alibaba (US) Technology Co., Ltd.GBQUIC82026-10-11 04:54
165.227.238.235AS14061 DigitalOcean, LLCGBUnrecognised72026-10-11 02:59
86.25.66.22AS5089 Virgin MediaGBUnrecognised62026-10-08 00:28
193.163.125.139AS211298 Driftnet LtdGBUnrecognised62026-10-10 22:23
193.163.125.170AS211298 Driftnet LtdGBUnrecognised52026-10-10 22:56
193.163.125.173AS211298 Driftnet LtdGBDNS52026-10-11 02:48
193.163.125.241AS211298 Driftnet LtdGBSOAP52026-10-08 22:52
193.163.125.151AS211298 Driftnet LtdGBUnrecognised52026-10-11 05:37
193.163.125.167AS211298 Driftnet LtdGBUnrecognised52026-10-11 06:50
193.163.125.116AS211298 Driftnet LtdGBUnrecognised52026-10-09 03:09
193.163.125.166AS211298 Driftnet LtdGBSNMP52026-10-11 08:43
193.163.125.178AS211298 Driftnet LtdGBUnrecognised52026-10-10 17:59
193.163.125.130AS211298 Driftnet LtdGBSIP42026-10-10 23:43
178.79.137.171AS63949 Akamai Connected CloudGBUnrecognised42026-10-07 13:25
212.71.250.62AS63949 Akamai Connected CloudGBUnrecognised42026-10-07 01:38
193.163.125.231AS211298 Driftnet LtdGBUnrecognised42026-10-11 02:36
193.163.125.137AS211298 Driftnet LtdGBUnrecognised42026-10-10 14:10

Latest datagrams