UDP traffic
Datagrams matching ip:103.123.175.6 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
3
Datagrams
1
Source addresses
1
Networks
1
Countries
3
Destination ports
Traffic by type
Unrecognised
3 datagrams from 1 sourceDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 1900/udp
payload bytes
00000000 5d 2e 7f 08 24 75 |]...$u|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| mDNS | 5353/udp | 1 | 1 | 2 to 10 |
| SSDP | 1900/udp | 1 | 1 | 30.8 |
| Memcached | 11211/udp | 1 | 1 | 10,000 to 51,000 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 103.123.175.6 | AS150968 PT Jaringanku Media Telekomunikasi | ID | Unrecognised | 3 | 2026-10-06 22:09 |
Latest datagrams
payload bytes
00000000 5d 2e 7f 08 24 75 |]...$u|
payload bytes
00000000 30 2e 16 45 14 7b 1e 2b 36 66 61 66 23 3f 60 3e |0..E.{.+6faf#?`>| 00000010 1e 1d 17 13 63 3b 05 25 2c 4a 3e 68 1c 72 53 4c |....c;.%,J>h.rSL| 00000020 47 6a 11 5c 65 89 32 |Gj.\e.2|payload bytes
00000000 6d 2e 32 6f 41 5e 58 10 6d 35 10 53 46 62 fd e8 |m.2oA^X.m5.SFb..|