HoneyLabs

UDP traffic

Datagrams matching port:500 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

51

Datagrams

38

Source addresses

12

Networks

6

Countries

1

Destination ports

Traffic by type

Unrecognised

51 datagrams from 38 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 500/udp

U·)·sI·! "·("·l·h·(·ޠ·B|㥏·@bE·V·|ٶ·R·`c·f·n0·@}·2·x·3·rc9M9·c·dž·Ԩ·J

payload bytes
00000000  55 14 d8 29 aa 73 49 c0  00 00 00 00 00 00 00 00  |U..).sI.........|
00000010  21 20 22 08 00 00 00 00  00 00 01 28 22 00 00 6c  |! "........("..l|
00000020  00 00 00 68 01 01 00 0b  03 00 00 0c 01 00 00 0c  |...h............|
00000030  80 0e 01 00 03 00 00 0c  01 00 00 0c 80 0e 00 80  |................|
00000040  03 00 00 08 01 00 00 03  03 00 00 08 01 00 00 02  |................|
00000050  03 00 00 08 02 00 00 02  03 00 00 08 02 00 00 01  |................|
00000060  03 00 00 08 03 00 00 02  03 00 00 08 03 00 00 01  |................|
00000070  03 00 00 08 04 00 00 02  03 00 00 08 04 00 00 05  |................|
00000080  00 00 00 08 04 00 00 0e  28 00 00 88 00 02 00 00  |........(.......|
00000090  f1 de a0 01 e3 a1 14 42  7c e3 a5 8f 8e fb b4 e8  |.......B|.......|
000000a0  40 62 45 f6 0e b5 e7 56  98 14 a4 7c d9 b6 8c c0  |@bE....V...|....|
000000b0  d3 52 a5 a9 60 63 ad 07  66 00 6e 30 b2 40 7d f1  |.R..`c..f.n0.@}.|
000000c0  32 14 78 ab a8 85 33 84  8e 17 72 63 39 4d 39 f8  |2.x...3...rc9M9.|
000000d0  bd 18 63 ec c7 86 e8 d4  a8 df c2 12 cb 4a 12 1d  |..c..........J..|
000000e0  77 fb a1 8b e0 0c e9 89  7f e3 97 93 4d 28 fb e9  |w...........M(..|
000000f0  a3 84 49 78 1b 64 84 75  4f 31 b5 63 fd f7 24 20  |..Ix.d.uO1.c..$ |

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
139.162.116.160AS63949 Akamai Connected CloudJPUnrecognised92026-10-11 06:19
103.203.57.10AS136180 Beijing Tiantexin Tech. Co., Ltd.CNUnrecognised32026-10-10 17:42
103.203.57.24AS136180 Beijing Tiantexin Tech. Co., Ltd.CNUnrecognised22026-10-10 18:33
193.163.125.137AS211298 Driftnet LtdGBUnrecognised22026-10-10 14:10
103.203.57.27AS136180 Beijing Tiantexin Tech. Co., Ltd.CNUnrecognised22026-10-11 03:42
40.119.27.191AS8075 Microsoft CorporationUSUnrecognised12026-10-10 15:22
148.153.188.246AS63199 CDS Global Cloud Co., LtdUSUnrecognised12026-10-10 23:44
64.62.197.221AS6939 Hurricane Electric LLCUSUnrecognised12026-10-11 00:31
64.62.197.43AS6939 Hurricane Electric LLCUSUnrecognised12026-10-11 06:02
198.235.24.82AS396982 Google LLCUSUnrecognised12026-10-10 08:53
64.62.197.60AS6939 Hurricane Electric LLCUSUnrecognised12026-10-10 08:03
4.148.17.55AS8075 Microsoft CorporationUSUnrecognised12026-10-10 15:23
216.226.76.20AS50219 Valence Technology Co.USUnrecognised12026-10-10 22:25
20.46.245.36AS8075 Microsoft CorporationUSUnrecognised12026-10-10 23:16
66.132.186.250AS398324 Censys, Inc.USUnrecognised12026-10-10 10:08
147.185.132.109AS396982 Google LLCUSUnrecognised12026-10-11 07:06
20.163.35.254AS8075 Microsoft CorporationUSUnrecognised12026-10-10 15:37
52.180.137.18AS8075 Microsoft CorporationUSUnrecognised12026-10-10 23:05
64.62.197.191AS6939 Hurricane Electric LLCUSUnrecognised12026-10-11 05:44
198.235.24.90AS396982 Google LLCUSUnrecognised12026-10-10 10:49

Latest datagrams