HoneyLabs

UDP traffic

Datagrams matching port:88 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

7

Datagrams

7

Source addresses

3

Networks

2

Countries

1

Destination ports

Traffic by type

Other services

5 datagrams from 5 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest Kerberos datagram, to 88/udp

j·0· ·x0v·@·0· 0·Xpanse· REALM.com·0·0·krbtgt· REALM.com·20231123004255Z· Jv·0·

payload bytes
00000000  6a 81 87 30 81 84 a1 03  02 01 05 a2 03 02 01 0a  |j..0............|
00000010  a4 78 30 76 a0 07 03 05  00 40 00 00 00 a1 13 30  |.x0v.....@.....0|
00000020  11 a0 03 02 01 01 a1 0a  30 08 1b 06 58 70 61 6e  |........0...Xpan|
00000030  73 65 a2 0b 1b 09 52 45  41 4c 4d 2e 63 6f 6d a3  |se....REALM.com.|
00000040  1e 30 1c a0 03 02 01 02  a1 15 30 13 1b 06 6b 72  |.0........0...kr|
00000050  62 74 67 74 1b 09 52 45  41 4c 4d 2e 63 6f 6d a5  |btgt..REALM.com.|
00000060  11 18 0f 32 30 32 33 31  31 32 33 30 30 34 32 35  |...2023112300425|
00000070  35 5a a7 06 02 04 09 4a  76 81 a8 0e 30 0c 02 01  |5Z.....Jv...0...|
00000080  12 02 01 11 02 01 10 02  01 17                    |..........|

Unrecognised

2 datagrams from 2 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 88/udp

j·e0·b· ·U0S·P·NM·0·0·krbtgt·NM·20261011024929Z·X$·0·0·

payload bytes
00000000  6a 81 65 30 81 62 a1 03  02 01 05 a2 03 02 01 0a  |j.e0.b..........|
00000010  a4 81 55 30 53 a0 07 03  05 00 50 00 00 00 a2 04  |..U0S.....P.....|
00000020  1b 02 4e 4d a3 17 30 15  a0 03 02 01 00 a1 0e 30  |..NM..0........0|
00000030  0c 1b 06 6b 72 62 74 67  74 1b 02 4e 4d a5 11 18  |...krbtgt..NM...|
00000040  0f 32 30 32 36 31 30 31  31 30 32 34 39 32 39 5a  |.20261011024929Z|
00000050  a7 06 02 04 58 24 d1 30  a8 0e 30 0c 02 01 12 02  |....X$.0..0.....|
00000060  01 11 02 01 17 02 01 03                           |........|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
198.235.24.193AS396982 Google LLCUSKerberos12026-10-11 04:46
193.163.125.173AS211298 Driftnet LtdGBUnrecognised12026-10-11 02:48
66.132.172.233AS398324 Censys, Inc.USUnrecognised12026-10-10 21:23
198.235.24.185AS396982 Google LLCUSKerberos12026-10-11 03:00
205.210.31.82AS396982 Google LLCUSKerberos12026-10-10 22:17
198.235.24.113AS396982 Google LLCUSKerberos12026-10-10 10:15
205.210.31.223AS396982 Google LLCUSKerberos12026-10-11 00:10

Latest datagrams