HoneyLabs

UDP traffic

Datagrams matching proto:google sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

48

Datagrams

13

Source addresses

7

Networks

3

Countries

2

Destination ports

Traffic by type

Service queries

25 datagrams from 12 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

DNS query A www.google.com

payload bytes
00000000  ae 0d 01 00 00 01 00 00  00 00 00 00 03 77 77 77  |.............www|
00000010  06 67 6f 6f 67 6c 65 03  63 6f 6d 00 00 01 00 01  |.google.com.....|

Other services

23 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest GOOGLE datagram, to 443/udp

·.·cՄ·Q043·\·Ժ·C·C·CHLO·PAD·SNI·STK·,·VER·0·CCS·@·NONC`·AEADd·UAID·SCID·TCID·PDMD·SMHL·ICSL·NONP·PUBS·MIDS·SCLS·KEXS·XLCT·CSCT·COPT·CCRT$·IRTT(·CFCW,·SFCW0·--------------------

payload bytes
00000000  0d 80 2e c4 63 d5 84 95  03 51 30 34 33 01 e5 1a  |....c....Q043...|
00000010  5c f8 aa aa d4 ba 10 43  de 43 a0 01 04 00 43 48  |\......C.C....CH|
00000020  4c 4f 19 00 00 00 50 41  44 00 e8 01 00 00 53 4e  |LO....PAD.....SN|
00000030  49 00 f6 01 00 00 53 54  4b 00 2c 02 00 00 56 45  |I.....STK.,...VE|
00000040  52 00 30 02 00 00 43 43  53 00 40 02 00 00 4e 4f  |R.0...CCS.@...NO|
00000050  4e 43 60 02 00 00 41 45  41 44 64 02 00 00 55 41  |NC`...AEADd...UA|
00000060  49 44 94 02 00 00 53 43  49 44 a4 02 00 00 54 43  |ID....SCID....TC|
00000070  49 44 a8 02 00 00 50 44  4d 44 ac 02 00 00 53 4d  |ID....PDMD....SM|
00000080  48 4c b0 02 00 00 49 43  53 4c b4 02 00 00 4e 4f  |HL....ICSL....NO|
00000090  4e 50 d4 02 00 00 50 55  42 53 f4 02 00 00 4d 49  |NP....PUBS....MI|
000000a0  44 53 f8 02 00 00 53 43  4c 53 fc 02 00 00 4b 45  |DS....SCLS....KE|
000000b0  58 53 00 03 00 00 58 4c  43 54 08 03 00 00 43 53  |XS....XLCT....CS|
000000c0  43 54 08 03 00 00 43 4f  50 54 14 03 00 00 43 43  |CT....COPT....CC|
000000d0  52 54 24 03 00 00 49 52  54 54 28 03 00 00 43 46  |RT$...IRTT(...CF|
000000e0  43 57 2c 03 00 00 53 46  43 57 30 03 00 00 2d 2d  |CW,...SFCW0...--|
000000f0  2d 2d 2d 2d 2d 2d 2d 2d  2d 2d 2d 2d 2d 2d 2d 2d  |----------------|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp251228 to 54

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

DNS questions

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
185.200.118.46AS9009 M247 Europe SRLGBGOOGLE232026-10-10 22:30
185.191.236.38AS264617 GRUPO PANAGLOBAL 15 S.ACHDNS62026-10-08 20:29
13.58.25.240AS16509 Amazon.com, Inc.USDNS42026-10-07 13:16
18.226.68.29AS16509 Amazon.com, Inc.USDNS42026-10-06 13:13
52.14.245.101AS16509 Amazon.com, Inc.USDNS22026-10-08 12:08
18.188.181.94AS16509 Amazon.com, Inc.USDNS22026-10-10 12:34
13.59.254.158AS16509 Amazon.com, Inc.USDNS12026-10-10 13:51
71.6.134.232AS10439 CariNet, Inc.USDNS12026-10-06 13:54
165.227.88.201AS14061 DigitalOcean, LLCUSDNS12026-10-05 21:37
71.6.134.231AS10439 CariNet, Inc.USDNS12026-10-10 14:59
216.226.76.10AS50219 Valence Technology Co.USDNS12026-10-10 14:04
71.6.134.236AS10439 CariNet, Inc.USDNS12026-10-08 03:30
64.89.163.247AS401626 Netiface America, Inc.USDNS12026-10-09 00:54

Latest datagrams