HoneyLabs

UDP traffic

Datagrams matching proto:kerberos sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

5

Datagrams

5

Source addresses

1

Networks

1

Countries

1

Destination ports

Traffic by type

Other services

5 datagrams from 5 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest Kerberos datagram, to 88/udp

j·0· ·x0v·@·0· 0·Xpanse· REALM.com·0·0·krbtgt· REALM.com·20231123004255Z· Jv·0·

payload bytes
00000000  6a 81 87 30 81 84 a1 03  02 01 05 a2 03 02 01 0a  |j..0............|
00000010  a4 78 30 76 a0 07 03 05  00 40 00 00 00 a1 13 30  |.x0v.....@.....0|
00000020  11 a0 03 02 01 01 a1 0a  30 08 1b 06 58 70 61 6e  |........0...Xpan|
00000030  73 65 a2 0b 1b 09 52 45  41 4c 4d 2e 63 6f 6d a3  |se....REALM.com.|
00000040  1e 30 1c a0 03 02 01 02  a1 15 30 13 1b 06 6b 72  |.0........0...kr|
00000050  62 74 67 74 1b 09 52 45  41 4c 4d 2e 63 6f 6d a5  |btgt..REALM.com.|
00000060  11 18 0f 32 30 32 33 31  31 32 33 30 30 34 32 35  |...2023112300425|
00000070  35 5a a7 06 02 04 09 4a  76 81 a8 0e 30 0c 02 01  |5Z.....Jv...0...|
00000080  12 02 01 11 02 01 10 02  01 17                    |..........|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
198.235.24.193AS396982 Google LLCUSKerberos12026-10-11 04:46
198.235.24.185AS396982 Google LLCUSKerberos12026-10-11 03:00
205.210.31.82AS396982 Google LLCUSKerberos12026-10-10 22:17
198.235.24.113AS396982 Google LLCUSKerberos12026-10-10 10:15
205.210.31.223AS396982 Google LLCUSKerberos12026-10-11 00:10

Latest datagrams