HoneyLabs

UDP traffic

Datagrams matching port:520 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

56

Datagrams

35

Source addresses

15

Networks

10

Countries

1

Destination ports

Traffic by type

Service queries

2 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 520/udp

·D·

payload bytes
00000000  01 01 00 00 00 02 00 00  44 00 00 00 00 00 00 00  |........D.......|
00000010  00 00 00 00 00 00 00 0f                           |........|

Unrecognised

54 datagrams from 34 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 520/udp

·D·

payload bytes
00000000  01 01 00 00 00 02 00 00  44 00 00 00 00 00 00 00  |........D.......|
00000010  00 00 00 00 00 00 00 0f                           |........|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
RIPv1520/udp5434131.24
DNS520/udp2128 to 54

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
185.94.111.1AS51115 HLL LLCRUUnrecognised82026-10-08 22:13
212.71.250.62AS63949 Akamai Connected CloudGBUnrecognised42026-10-07 01:38
146.88.241.80AS20052 Arbor Networks, Inc.USUnrecognised32026-10-09 12:45
16.5.0.234AS401661 EMBNEX, LLCBRUnrecognised32026-10-05 17:37
157.230.83.56AS14061 DigitalOcean, LLCUSUnrecognised22026-10-09 17:23
185.226.197.28AS21859 Zenlayer IncPTUnrecognised22026-10-10 02:42
47.84.101.219AS45102 Alibaba (US) Technology Co., Ltd.SGDNS22026-10-06 07:35
206.189.14.75AS14061 DigitalOcean, LLCNLUnrecognised22026-10-07 00:19
146.88.241.170AS20052 Arbor Networks, Inc.USUnrecognised22026-10-09 13:46
137.184.210.250AS14061 DigitalOcean, LLCUSUnrecognised22026-10-05 13:50
193.47.62.187AS216014 BestDC LimitedBGUnrecognised22026-10-07 02:14
198.235.24.242AS396982 Google LLCUSUnrecognised12026-10-07 14:33
66.132.186.218AS398324 Censys, Inc.USUnrecognised12026-10-05 13:16
146.88.241.100AS20052 Arbor Networks, Inc.USUnrecognised12026-10-06 07:03
91.230.168.118AS213412 ONYPHE SASUSUnrecognised12026-10-10 09:23
93.174.95.106AS202425 IP Volume incNLUnrecognised12026-10-05 14:17
216.25.89.101AS396982 Google LLCUSUnrecognised12026-10-10 13:42
109.105.210.62AS21859 Zenlayer IncPTUnrecognised12026-10-09 08:12
91.230.168.114AS213412 ONYPHE SASUSUnrecognised12026-10-07 01:19
103.210.22.74AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITSGUnrecognised12026-10-08 07:55

Latest datagrams