HoneyLabs

UDP traffic

Datagrams matching port:502 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

29

Datagrams

24

Source addresses

3

Networks

3

Countries

1

Destination ports

Traffic by type

Unrecognised

29 datagrams from 24 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 502/udp

U·)·sI·! "·("·l·h·(·ޠ·B|㥏·@bE·V·|ٶ·R·`c·f·n0·@}·2·x·3·rc9M9·c·dž·Ԩ·J

payload bytes
00000000  55 14 d8 29 aa 73 49 c0  00 00 00 00 00 00 00 00  |U..).sI.........|
00000010  21 20 22 08 00 00 00 00  00 00 01 28 22 00 00 6c  |! "........("..l|
00000020  00 00 00 68 01 01 00 0b  03 00 00 0c 01 00 00 0c  |...h............|
00000030  80 0e 01 00 03 00 00 0c  01 00 00 0c 80 0e 00 80  |................|
00000040  03 00 00 08 01 00 00 03  03 00 00 08 01 00 00 02  |................|
00000050  03 00 00 08 02 00 00 02  03 00 00 08 02 00 00 01  |................|
00000060  03 00 00 08 03 00 00 02  03 00 00 08 03 00 00 01  |................|
00000070  03 00 00 08 04 00 00 02  03 00 00 08 04 00 00 05  |................|
00000080  00 00 00 08 04 00 00 0e  28 00 00 88 00 02 00 00  |........(.......|
00000090  f1 de a0 01 e3 a1 14 42  7c e3 a5 8f 8e fb b4 e8  |.......B|.......|
000000a0  40 62 45 f6 0e b5 e7 56  98 14 a4 7c d9 b6 8c c0  |@bE....V...|....|
000000b0  d3 52 a5 a9 60 63 ad 07  66 00 6e 30 b2 40 7d f1  |.R..`c..f.n0.@}.|
000000c0  32 14 78 ab a8 85 33 84  8e 17 72 63 39 4d 39 f8  |2.x...3...rc9M9.|
000000d0  bd 18 63 ec c7 86 e8 d4  a8 df c2 12 cb 4a 12 1d  |..c..........J..|
000000e0  77 fb a1 8b e0 0c e9 89  7f e3 97 93 4d 28 fb e9  |w...........M(..|
000000f0  a3 84 49 78 1b 64 84 75  4f 31 b5 63 fd f7 24 20  |..Ix.d.uO1.c..$ |

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
16.5.0.234AS401661 EMBNEX, LLCBRUnrecognised62026-10-05 17:10
40.90.227.189AS8075 Microsoft CorporationUSUnrecognised12026-10-06 05:01
134.33.97.182AS8075 Microsoft CorporationUSUnrecognised12026-10-09 16:24
172.180.64.139AS8075 Microsoft CorporationUSUnrecognised12026-10-07 22:58
20.169.90.245AS8075 Microsoft CorporationUSUnrecognised12026-10-07 01:55
52.186.178.27AS8075 Microsoft CorporationUSUnrecognised12026-10-06 04:48
35.203.210.127AS396982 Google LLCGBUnrecognised12026-10-08 21:35
20.169.85.34AS8075 Microsoft CorporationUSUnrecognised12026-10-08 19:54
4.148.240.254AS8075 Microsoft CorporationUSUnrecognised12026-10-09 16:33
40.90.236.53AS8075 Microsoft CorporationUSUnrecognised12026-10-08 19:46
20.168.117.0AS8075 Microsoft CorporationUSUnrecognised12026-10-08 19:44
162.216.150.241AS396982 Google LLCUSUnrecognised12026-10-08 09:37
172.174.129.234AS8075 Microsoft CorporationUSUnrecognised12026-10-07 01:58
20.14.94.107AS8075 Microsoft CorporationUSUnrecognised12026-10-10 13:13
162.216.150.28AS396982 Google LLCUSUnrecognised12026-10-09 03:57
35.203.210.115AS396982 Google LLCGBUnrecognised12026-10-10 06:30
162.216.150.96AS396982 Google LLCUSUnrecognised12026-10-09 14:09
48.216.210.148AS8075 Microsoft CorporationUSUnrecognised12026-10-07 22:57
20.38.35.165AS8075 Microsoft CorporationUSUnrecognised12026-10-09 16:31
20.106.212.228AS8075 Microsoft CorporationUSUnrecognised12026-10-06 04:56

Latest datagrams