UDP traffic
Datagrams matching port:5353 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
30
Datagrams
24
Source addresses
15
Networks
9
Countries
1
Destination ports
Traffic by type
Service queries
21 datagrams from 17 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 5353/udp
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
Unrecognised
9 datagrams from 8 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 5353/udp
payload bytes
00000000 12 2e 23 3e 0a 1b 00 12 5e 1f 57 79 71 39 36 4e |..#>....^.Wyq96N| 00000010 39 40 27 24 73 0a 19 6d 1c 70 3c 7c 7a 13 6f 0c |9@'$s..m.p<|z.o.| 00000020 0d 12 4a 17 2e 4b 2a 0c 6a 01 05 5b 3a 3c 29 74 |..J..K*.j..[:<)t| 00000030 7c 51 18 6f 5b 32 5c 77 22 00 01 ||Q.o[2\w"..|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| mDNS | 5353/udp | 30 | 24 | 2 to 10 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
- 5353/udp DNS30
DNS questions
DNS record types
Networks
- AS396982 Google LLC from 7 sources7
- AS45102 Alibaba (US) Technology Co., Ltd. from 1 source5
- AS6939 Hurricane Electric LLC from 4 sources4
- AS50219 Valence Technology Co. from 1 source2
- AS20052 Arbor Networks, Inc. from 1 source2
- AS9808 China Mobile Communications Group Co., L from 1 source1
- AS398324 Censys, Inc. from 1 source1
- AS19994 Rackspace Hosting from 1 source1
- AS60024 Hk Cedoc Limited from 1 source1
- AS11814 Distributel Communications Limited from 1 source1
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 47.245.84.83 | AS45102 Alibaba (US) Technology Co., Ltd. | SG | DNS | 5 | 2026-10-10 05:06 |
| 146.88.241.70 | AS20052 Arbor Networks, Inc. | US | DNS | 2 | 2026-10-11 02:25 |
| 216.226.77.30 | AS50219 Valence Technology Co. | US | DNS | 2 | 2026-10-10 13:14 |
| 66.132.172.236 | AS398324 Censys, Inc. | US | DNS | 1 | 2026-10-10 18:32 |
| 174.138.216.234 | AS11814 Distributel Communications Limited | CA | Unrecognised | 1 | 2026-10-11 03:53 |
| 184.105.247.235 | AS6939 Hurricane Electric LLC | US | DNS | 1 | 2026-10-10 09:03 |
| 205.210.31.60 | AS396982 Google LLC | US | DNS | 1 | 2026-10-11 00:26 |
| 216.25.89.147 | AS396982 Google LLC | US | mDNS | 1 | 2026-10-10 15:54 |
| 139.202.232.10 | AS4134 Chinanet | CN | Unrecognised | 1 | 2026-10-10 09:02 |
| 65.49.1.73 | AS6939 Hurricane Electric LLC | US | DNS | 1 | 2026-10-10 04:32 |
| 64.62.156.50 | AS6939 Hurricane Electric LLC | US | DNS | 1 | 2026-10-11 04:13 |
| 162.216.149.250 | AS396982 Google LLC | US | mDNS | 1 | 2026-10-10 17:53 |
| 78.232.50.178 | AS12876 Scaleway SAS | FR | DNS | 1 | 2026-10-10 23:51 |
| 176.65.149.254 | AS51396 Pfcloud UG (haftungsbeschrankt) | NL | DNS | 1 | 2026-10-10 15:40 |
| 78.107.31.154 | AS8402 PVimpelCom | RU | Unrecognised | 1 | 2026-10-10 18:08 |
| 120.192.235.150 | AS9808 China Mobile Communications Group Co., L | CN | Unrecognised | 1 | 2026-10-10 14:32 |
| 64.62.156.79 | AS6939 Hurricane Electric LLC | US | DNS | 1 | 2026-10-10 05:21 |
| 166.78.113.115 | AS19994 Rackspace Hosting | US | Unrecognised | 1 | 2026-10-11 01:26 |
| 205.210.31.84 | AS396982 Google LLC | US | DNS | 1 | 2026-10-10 18:40 |
| 198.235.24.176 | AS396982 Google LLC | US | DNS | 1 | 2026-10-10 18:24 |
Latest datagrams
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 12 2e 23 3e 0a 1b 00 12 5e 1f 57 79 71 39 36 4e |..#>....^.Wyq96N| 00000010 39 40 27 24 73 0a 19 6d 1c 70 3c 7c 7a 13 6f 0c |9@'$s..m.p<|z.o.| 00000020 0d 12 4a 17 2e 4b 2a 0c 6a 01 05 5b 3a 3c 29 74 |..J..K*.j..[:<)t| 00000030 7c 51 18 6f 5b 32 5c 77 22 00 01 ||Q.o[2\w"..|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 69 2e 1e 33 0c 38 3f 03 43 7f 2e 48 6e 38 11 31 |i..3.8?.C..Hn8.1| 00000010 1a 25 4d 27 77 69 08 98 |.%M'wi..|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 00 00 01 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 00 00 00 00 00 01 00 00 00 00 00 00 09 5f 73 65 |............._se| 00000010 72 76 69 63 65 73 07 5f 64 6e 73 2d 73 64 04 5f |rvices._dns-sd._| 00000020 75 64 70 05 6c 6f 63 61 6c 00 00 0c 00 01 |udp.local.....|
payload bytes
00000000 3b 2e 47 32 27 6d 00 4b 5b 3a 44 74 2b 7f 0e 1f |;.G2'm.K[:Dt+...| 00000010 0d 25 27 4c 21 7b 63 23 2a 10 76 0a 16 7e 0b 51 |.%'L!{c#*.v..~.Q| 00000020 59 53 8a 66 |YS.f|payload bytes
00000000 32 2e 64 e6 b0 |2.d..|
payload bytes
00000000 34 ef 01 00 00 01 00 00 00 00 00 00 07 56 45 52 |4............VER| 00000010 53 53 49 4f 4e 04 42 49 4e 44 00 00 10 00 03 |SSION.BIND.....|
payload bytes
00000000 34 ef 01 00 00 01 00 00 00 00 00 00 07 56 45 52 |4............VER| 00000010 53 53 49 4f 4e 04 42 49 4e 44 00 00 10 00 03 |SSION.BIND.....|