UDP traffic
Datagrams matching port:19 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Your plan searches up to 7d, so 30d was shortened. Plans
87
Datagrams
52
Source addresses
15
Networks
7
Countries
1
Destination ports
Traffic by type
Other services
7 datagrams from 2 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest HTTP datagram, to 19/udp
payload bytes
00000000 47 45 54 20 2f 20 48 54 54 50 2f 31 2e 31 0d 0a |GET / HTTP/1.1..| 00000010 48 6f 73 74 3a 20 77 77 77 0d 0a 0d 0a |Host: www....|
Unrecognised
80 datagrams from 50 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 19/udp
payload bytes
00000000 0a |.|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| CharGEN | 19/udp | 87 | 52 | 358.8 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
- 19/udp CharGEN87
Networks
- AS6939 Hurricane Electric LLC from 19 sources20
- AS209588 Flyservers S.A. from 1 source17
- AS20052 Arbor Networks, Inc. from 6 sources10
- AS398324 Censys, Inc. from 6 sources6
- AS51396 Pfcloud UG (haftungsbeschrankt) from 2 sources6
- AS396982 Google LLC from 6 sources6
- AS63949 Akamai Connected Cloud from 1 source4
- AS202425 IP Volume inc from 1 source4
- AS21859 Zenlayer Inc from 3 sources3
- AS401661 EMBNEX, LLC from 1 source3
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 141.98.83.48 | AS209588 Flyservers S.A. | PA | Unrecognised | 17 | 2026-10-10 08:46 |
| 176.65.149.208 | AS51396 Pfcloud UG (haftungsbeschrankt) | NL | Unrecognised | 5 | 2026-10-11 03:28 |
| 172.105.106.177 | AS63949 Akamai Connected Cloud | CA | Unrecognised | 4 | 2026-10-06 20:59 |
| 185.242.226.65 | AS202425 IP Volume inc | US | HTTP | 4 | 2026-10-07 10:54 |
| 16.5.0.234 | AS401661 EMBNEX, LLC | BR | Unrecognised | 3 | 2026-10-05 17:41 |
| 52.73.169.169 | AS14618 Amazon.com, Inc. | US | HTTP | 3 | 2026-10-05 21:29 |
| 146.88.241.100 | AS20052 Arbor Networks, Inc. | US | Unrecognised | 3 | 2026-10-11 02:25 |
| 146.88.241.20 | AS20052 Arbor Networks, Inc. | US | Unrecognised | 2 | 2026-10-06 04:27 |
| 146.88.240.41 | AS20052 Arbor Networks, Inc. | US | Unrecognised | 2 | 2026-10-08 07:04 |
| 64.62.197.173 | AS6939 Hurricane Electric LLC | US | Unrecognised | 2 | 2026-10-09 01:50 |
| 65.49.1.81 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-06 02:58 |
| 205.210.31.252 | AS396982 Google LLC | US | Unrecognised | 1 | 2026-10-06 12:17 |
| 216.25.89.65 | AS396982 Google LLC | US | Unrecognised | 1 | 2026-10-07 12:48 |
| 64.62.197.167 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-09 01:12 |
| 147.185.132.234 | AS396982 Google LLC | US | Unrecognised | 1 | 2026-10-09 17:15 |
| 64.62.156.119 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-11 00:19 |
| 64.62.156.92 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-10 02:18 |
| 185.180.141.10 | AS21859 Zenlayer Inc | PT | Unrecognised | 1 | 2026-10-09 08:10 |
| 66.132.186.250 | AS398324 Censys, Inc. | US | Unrecognised | 1 | 2026-10-08 05:05 |
| 64.62.197.184 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-07 06:38 |
Latest datagrams
payload bytes
00000000 0a |.|
payload bytes
00000000 01 |.|
payload bytes
00000000 0a |.|
payload bytes
00000000 0a |.|
payload bytes
00000000 61 |a|
payload bytes
00000000 61 |a|
payload bytes
00000000 0a |.|
payload bytes
00000000 0a |.|
payload bytes
00000000 0a |.|
payload bytes
00000000 72 fe 1d 13 00 00 00 00 00 00 00 02 00 01 86 a0 |r...............| 00000010 00 01 97 7c 00 00 00 00 00 00 00 00 00 00 00 00 |...|............| 00000020 00 00 00 00 00 00 00 00 |........|
payload bytes
00000000 ff |.|
payload bytes
00000000 ff |.|
payload bytes
00000000 ff |.|
payload bytes
00000000 ff |.|
payload bytes
00000000 0a |.|