UDP traffic
Datagrams matching port:53 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
714
Datagrams
237
Source addresses
46
Networks
23
Countries
1
Destination ports
Traffic by type
Service queries
675 datagrams from 204 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 26 ea 01 00 00 01 00 00 00 00 00 00 03 69 6d 73 |&............ims| 00000010 06 6d 6e 63 30 30 31 06 6d 63 63 32 36 32 0b 33 |.mnc001.mcc262.3| 00000020 67 70 70 6e 65 74 77 6f 72 6b 03 6f 72 67 00 00 |gppnetwork.org..| 00000030 01 00 01 |...|
Other services
1 datagrams from 1 sourceFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest HTTP datagram, to 53/udp
payload bytes
00000000 47 45 54 20 2f 20 48 54 54 50 2f 31 2e 31 0d 0a |GET / HTTP/1.1..| 00000010 48 6f 73 74 3a 20 77 77 77 0d 0a 0d 0a |Host: www....|
Unrecognised
38 datagrams from 36 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 53/udp
Payload bytes withheld: they contain the sensor's address.
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| DNS | 53/udp | 675 | 204 | 28 to 54 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
- 53/udp DNS714
DNS questions
DNS record types
Networks
- AS396982 Google LLC from 59 sources160
- AS16509 Amazon.com, Inc. from 7 sources74
- AS215925 Vpsvault.host Ltd from 4 sources46
- AS51396 Pfcloud UG (haftungsbeschrankt) from 4 sources39
- AS12876 Scaleway SAS from 2 sources38
- AS8075 Microsoft Corporation from 33 sources33
- AS219502 Storm Industries LLC from 2 sources30
- AS6939 Hurricane Electric LLC from 22 sources24
- AS209630 LLC Vash Kredit Bank from 1 source24
- AS14061 DigitalOcean, LLC from 17 sources24
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 45.135.193.115 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | DNS | 27 | 2026-10-11 02:15 |
| 151.243.11.230 | AS209630 LLC Vash Kredit Bank | AE | DNS | 24 | 2026-10-09 20:04 |
| 18.226.68.29 | AS16509 Amazon.com, Inc. | US | DNS | 23 | 2026-10-06 13:13 |
| 141.98.11.129 | AS209605 UAB Host Baltic | LT | DNS | 23 | 2026-10-11 07:50 |
| 185.73.23.133 | AS29484 Ruhr-Universitaet Bochum | DE | DNS | 23 | 2026-10-11 09:24 |
| 94.154.43.109 | AS219502 Storm Industries LLC | NL | DNS | 22 | 2026-10-09 08:45 |
| 51.158.205.203 | AS12876 Scaleway SAS | NL | DNS | 21 | 2026-10-11 07:31 |
| 45.205.1.231 | AS215925 Vpsvault.host Ltd | BR | DNS | 20 | 2026-10-11 01:20 |
| 45.198.224.251 | AS215925 Vpsvault.host Ltd | US | DNS | 19 | 2026-10-11 05:42 |
| 141.98.83.48 | AS209588 Flyservers S.A. | PA | DNS | 19 | 2026-10-11 06:13 |
| 216.180.246.141 | AS396982 Google LLC | US | DNS | 17 | 2026-10-10 11:12 |
| 216.180.246.230 | AS396982 Google LLC | US | DNS | 17 | 2026-10-07 11:04 |
| 216.180.246.225 | AS396982 Google LLC | US | DNS | 17 | 2026-10-07 11:15 |
| 216.180.246.217 | AS396982 Google LLC | US | DNS | 17 | 2026-10-07 16:46 |
| 62.210.142.176 | AS12876 Scaleway SAS | FR | DNS | 17 | 2026-10-10 16:28 |
| 216.180.246.101 | AS396982 Google LLC | US | DNS | 17 | 2026-10-10 11:02 |
| 13.58.25.240 | AS16509 Amazon.com, Inc. | US | DNS | 14 | 2026-10-07 13:16 |
| 52.14.245.101 | AS16509 Amazon.com, Inc. | US | DNS | 13 | 2026-10-08 12:08 |
| 185.94.111.1 | AS51115 HLL LLC | RU | DNS | 12 | 2026-10-10 18:34 |
| 18.188.181.94 | AS16509 Amazon.com, Inc. | US | DNS | 10 | 2026-10-10 12:34 |
Latest datagrams
payload bytes
00000000 26 ea 01 00 00 01 00 00 00 00 00 00 03 69 6d 73 |&............ims| 00000010 06 6d 6e 63 30 30 31 06 6d 63 63 32 36 32 0b 33 |.mnc001.mcc262.3| 00000020 67 70 70 6e 65 74 77 6f 72 6b 03 6f 72 67 00 00 |gppnetwork.org..| 00000030 01 00 01 |...|
payload bytes
00000000 19 0e 01 00 00 01 00 00 00 00 00 00 03 69 6d 73 |.............ims| 00000010 06 6d 6e 63 30 30 31 06 6d 63 63 32 36 32 0b 33 |.mnc001.mcc262.3| 00000020 67 70 70 6e 65 74 77 6f 72 6b 03 6f 72 67 00 00 |gppnetwork.org..| 00000030 01 00 01 |...|
payload bytes
00000000 d2 66 01 00 00 01 00 00 00 00 00 00 03 69 6d 73 |.f...........ims| 00000010 06 6d 6e 63 30 30 31 06 6d 63 63 32 36 32 0b 33 |.mnc001.mcc262.3| 00000020 67 70 70 6e 65 74 77 6f 72 6b 03 6f 72 67 00 00 |gppnetwork.org..| 00000030 01 00 01 |...|
payload bytes
00000000 61 83 01 00 00 01 00 00 00 00 00 00 06 67 6f 6f |a............goo| 00000010 67 6c 65 03 63 6f 6d 00 00 01 00 01 |gle.com.....|
Payload bytes withheld: they contain the sensor's address.
Payload bytes withheld: they contain the sensor's address.
payload bytes
00000000 fa ce 01 00 00 01 00 00 00 00 00 00 07 64 6e 73 |.............dns| 00000010 73 63 61 6e 0c 73 68 61 64 6f 77 73 65 72 76 65 |scan.shadowserve| 00000020 72 03 6f 72 67 00 00 01 00 01 |r.org.....|
payload bytes
00000000 c8 f3 01 00 00 01 00 00 00 00 00 01 02 6e 69 00 |.............ni.| 00000010 00 ff 00 01 00 00 29 ff ff 00 00 00 00 00 00 |......)........|
Payload bytes withheld: they contain the sensor's address.
payload bytes
00000000 00 01 01 00 00 01 00 00 00 00 00 01 02 69 64 06 |.............id.| 00000010 73 65 72 76 65 72 00 00 10 00 03 00 00 29 10 00 |server.......)..| 00000020 00 00 80 00 00 04 00 03 00 00 |..........|
payload bytes
00000000 5f af 01 20 00 01 00 00 00 00 00 00 07 76 65 72 |_.. .........ver| 00000010 73 69 6f 6e 04 62 69 6e 64 00 00 10 00 03 00 |sion.bind......|
payload bytes
00000000 fa ce 01 00 00 01 00 00 00 00 00 00 07 64 6e 73 |.............dns| 00000010 73 63 61 6e 0c 73 68 61 64 6f 77 73 65 72 76 65 |scan.shadowserve| 00000020 72 03 6f 72 67 00 00 01 00 01 |r.org.....|
payload bytes
00000000 fa ce 01 00 00 01 00 00 00 00 00 00 07 64 6e 73 |.............dns| 00000010 73 63 61 6e 0c 73 68 61 64 6f 77 73 65 72 76 65 |scan.shadowserve| 00000020 72 03 6f 72 67 00 00 01 00 01 |r.org.....|
Payload bytes withheld: they contain the sensor's address.
payload bytes
00000000 45 67 01 00 00 01 00 00 00 00 00 01 04 66 65 72 |Eg...........fer| 00000010 63 03 67 6f 76 00 00 ff 00 01 00 00 29 ff ff 00 |c.gov.......)...| 00000020 00 00 00 00 00 |.....|