UDP traffic
Datagrams matching port:5351 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Your plan searches up to 7d, so 30d was shortened. Plans
121
Datagrams
94
Source addresses
12
Networks
7
Countries
1
Destination ports
Traffic by type
Service queries
6 datagrams from 5 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 5351/udp
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
Unrecognised
115 datagrams from 90 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 5351/udp
payload bytes
00000000 00 00 |..|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
- 5351/udp NAT-PMP121
DNS questions
DNS record types
- PTR4
Networks
- AS396982 Google LLC from 42 sources43
- AS6939 Hurricane Electric LLC from 22 sources23
- AS42237 w1n ltd from 1 source8
- AS43513 Sia Nano IT from 1 source8
- AS213412 ONYPHE SAS from 6 sources8
- AS398324 Censys, Inc. from 6 sources6
- AS8075 Microsoft Corporation from 6 sources6
- AS401661 EMBNEX, LLC from 1 source5
- AS63949 Akamai Connected Cloud from 3 sources5
- AS45102 Alibaba (US) Technology Co., Ltd. from 2 sources4
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 185.217.1.242 | AS42237 w1n ltd | SE | Unrecognised | 8 | 2026-10-10 03:16 |
| 31.170.22.206 | AS43513 Sia Nano IT | LV | Unrecognised | 8 | 2026-10-11 00:54 |
| 16.5.0.234 | AS401661 EMBNEX, LLC | BR | Unrecognised | 5 | 2026-10-05 18:27 |
| 139.162.186.195 | AS63949 Akamai Connected Cloud | DE | Unrecognised | 3 | 2026-10-10 21:54 |
| 47.254.154.232 | AS45102 Alibaba (US) Technology Co., Ltd. | DE | TFTP | 3 | 2026-10-09 23:45 |
| 91.230.168.117 | AS213412 ONYPHE SAS | US | Unrecognised | 2 | 2026-10-09 19:23 |
| 165.154.163.10 | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT | US | Unrecognised | 2 | 2026-10-07 19:01 |
| 91.231.89.165 | AS213412 ONYPHE SAS | FR | Unrecognised | 2 | 2026-10-09 19:38 |
| 65.49.1.79 | AS6939 Hurricane Electric LLC | US | Unrecognised | 2 | 2026-10-08 02:18 |
| 147.185.132.70 | AS396982 Google LLC | US | Unrecognised | 2 | 2026-10-09 08:00 |
| 91.231.89.95 | AS213412 ONYPHE SAS | FR | Unrecognised | 1 | 2026-10-07 01:29 |
| 64.62.156.13 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-09 02:13 |
| 216.25.89.125 | AS396982 Google LLC | US | Unrecognised | 1 | 2026-10-10 22:21 |
| 65.49.1.15 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-09 05:44 |
| 91.230.168.223 | AS213412 ONYPHE SAS | US | Unrecognised | 1 | 2026-10-07 01:22 |
| 205.210.31.234 | AS396982 Google LLC | US | Unrecognised | 1 | 2026-10-10 03:34 |
| 71.6.233.2 | AS10439 CariNet, Inc. | US | Unrecognised | 1 | 2026-10-06 03:38 |
| 64.62.197.4 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-07 08:25 |
| 64.62.197.120 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-10 03:00 |
| 64.62.197.202 | AS6939 Hurricane Electric LLC | US | Unrecognised | 1 | 2026-10-11 03:45 |
Latest datagrams
payload bytes
00000000 00 00 |..|
payload bytes
00000000 00 00 |..|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 |..|
payload bytes
00000000 00 00 |..|
payload bytes
00000000 00 02 00 00 0f a0 28 bd 00 00 02 58 |......(....X|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 00 00 00 00 |....|
payload bytes
00000000 02 01 00 00 00 00 0e 10 00 00 00 00 00 00 00 00 |................| 00000010 00 00 ff ff 00 00 00 00 dd 4d 29 77 27 9f 09 81 |.........M)w'...| 00000020 2b e8 b6 4e 11 00 00 00 00 00 00 00 00 00 00 00 |+..N............| 00000030 00 00 00 00 00 00 ff ff 00 00 00 00 |............|