HoneyLabs

UDP traffic

Datagrams matching proto:openvpn sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

1

Datagrams

1

Source addresses

1

Networks

1

Countries

1

Destination ports

Traffic by type

Other services

1 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest OpenVPN datagram, to 5353/udp

\.% z·~#p</·~:qTC$HCF Q·k·gX,R5*wU$}SHn·wz·1kct·+8U4 `6ub·M·p·8gW]d+%R;·MIM8,·

payload bytes
00000000  5c 2e 25 20 7a 06 7e 23  70 3c 2f 0c 7e 3a 71 54  |\.% z.~#p</.~:qT|
00000010  43 24 48 43 46 09 51 0b  02 6b 02 67 58 2c 52 35  |C$HCF.Q..k.gX,R5|
00000020  2a 77 55 24 7d 53 48 6e  10 77 7a 0e 31 6b 63 74  |*wU$}SHn.wz.1kct|
00000030  0f 2b 38 55 34 09 60 36  75 62 1e 4d 0e 70 02 38  |.+8U4.`6ub.M.p.8|
00000040  67 57 5d 64 2b 25 52 3b  1c 4d 49 4d 38 2c c3 f4  |gW]d+%R;.MIM8,..|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
mDNS5353/udp112 to 10

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
31.132.169.138AS57044 JSC ER-Telecom HoldingRUOpenVPN12026-10-07 03:18

Latest datagrams