HoneyLabs

UDP traffic

Datagrams matching port:4500 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

138

Datagrams

114

Source addresses

15

Networks

10

Countries

1

Destination ports

Traffic by type

Other services

3 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest HTTP datagram, to 4500/udp

payload bytes
00000000  47 45 54 20 2f 20 48 54  54 50 2f 31 2e 31 0d 0a  |GET / HTTP/1.1..|
00000010  48 6f 73 74 3a 20 77 77  77 0d 0a 0d 0a           |Host: www....|

Unrecognised

135 datagrams from 113 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 4500/udp

·P·4·(·$·p·$·p·$·p·$·p·$·

payload bytes
00000000  00 00 00 00 89 ec e2 de  18 86 e4 b9 00 00 00 00  |................|
00000010  00 00 00 00 01 10 02 00  00 00 00 00 00 00 01 50  |...............P|
00000020  00 00 01 34 00 00 00 01  00 00 00 01 00 00 01 28  |...4...........(|
00000030  01 01 00 08 03 00 00 24  01 01 00 00 80 01 00 05  |.......$........|
00000040  80 02 00 02 80 03 00 01  80 04 00 02 80 0b 00 01  |................|
00000050  00 0c 00 04 00 00 70 80  03 00 00 24 02 01 00 00  |......p....$....|
00000060  80 01 00 05 80 02 00 01  80 03 00 01 80 04 00 02  |................|
00000070  80 0b 00 01 00 0c 00 04  00 00 70 80 03 00 00 24  |..........p....$|
00000080  03 01 00 00 80 01 00 01  80 02 00 02 80 03 00 01  |................|
00000090  80 04 00 02 80 0b 00 01  00 0c 00 04 00 00 70 80  |..............p.|
000000a0  03 00 00 24 04 01 00 00  80 01 00 01 80 02 00 01  |...$............|
000000b0  80 03 00 01 80 04 00 02  80 0b 00 01 00 0c 00 04  |................|
000000c0  00 00 70 80 03 00 00 24  05 01 00 00 80 01 00 05  |..p....$........|
000000d0  80 02 00 02 80 03 00 01  80 04 00 01 80 0b 00 01  |................|
000000e0  00 0c 00 04 00 00 70 80  03 00 00 24 06 01 00 00  |......p....$....|
000000f0  80 01 00 05 80 02 00 01  80 03 00 01 80 04 00 01  |................|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
159.203.131.252AS14061 DigitalOcean, LLCUSUnrecognised42026-10-07 20:51
157.245.2.3AS14061 DigitalOcean, LLCUSUnrecognised42026-10-07 12:59
45.79.67.140AS63949 Akamai Connected CloudUSHTTP32026-10-10 08:04
80.82.77.139AS202425 IP Volume incNLUnrecognised22026-10-09 01:44
205.210.31.67AS396982 Google LLCUSUnrecognised22026-10-09 19:26
198.235.24.94AS396982 Google LLCUSUnrecognised22026-10-10 09:52
91.231.89.162AS213412 ONYPHE SASFRUnrecognised22026-10-09 09:11
193.163.125.159AS211298 Driftnet LtdGBUnrecognised22026-10-07 17:38
193.163.125.141AS211298 Driftnet LtdGBUnrecognised22026-10-09 06:55
66.132.159.34AS398324 Censys, Inc.USUnrecognised22026-10-09 20:06
205.210.31.212AS396982 Google LLCUSUnrecognised22026-10-06 18:21
91.230.168.114AS213412 ONYPHE SASUSUnrecognised22026-10-09 08:56
193.163.125.240AS211298 Driftnet LtdGBUnrecognised22026-10-05 20:22
198.235.24.226AS396982 Google LLCUSUnrecognised22026-10-09 10:12
193.163.125.178AS211298 Driftnet LtdGBUnrecognised22026-10-10 17:59
205.210.31.65AS396982 Google LLCUSUnrecognised22026-10-10 10:37
198.235.24.101AS396982 Google LLCUSUnrecognised22026-10-10 05:04
193.163.125.224AS211298 Driftnet LtdGBUnrecognised22026-10-08 20:48
193.163.125.134AS211298 Driftnet LtdGBUnrecognised22026-10-06 06:22
45.156.129.86AS211680 Sistemas Informaticos, S.A.PTUnrecognised12026-10-08 02:49

Latest datagrams