HoneyLabs

UDP traffic

Datagrams matching ip:193.163.125.122 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

2

Datagrams

1

Source addresses

1

Networks

1

Countries

2

Destination ports

Traffic by type

Service queries

1 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest Sun RPC datagram, to 2049/udp

·O·

payload bytes
00000000  9c 4f e6 84 00 00 00 00  00 00 00 02 00 01 86 a0  |.O..............|
00000010  00 00 00 04 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000020  00 00 00 00 00 00 00 00                           |........|

Other services

1 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest DTLS datagram, to 10443/udp

·y·y·h·Z·ж·^ ·VN·ȹ·\·UI·Nr·+·/· · ·,·0̨̩·7· · · ·

payload bytes
00000000  16 fe fd 00 00 00 00 00  00 00 00 00 85 01 00 00  |................|
00000010  79 00 00 00 00 00 00 00  79 fe fd d0 1d 68 c8 5a  |y.......y....h.Z|
00000020  8b d0 b6 da 1e b6 5e 0a  93 1e ab c2 56 4e e5 03  |......^.....VN..|
00000030  b4 c8 b9 04 5c e3 55 49  82 4e 72 00 00 00 18 c0  |....\.UI.Nr.....|
00000040  ac c0 ae c0 2b c0 2f c0  09 c0 13 c0 0a c0 14 c0  |....+./.........|
00000050  2c c0 30 cc a9 cc a8 01  00 00 37 00 0d 00 16 00  |,.0.......7.....|
00000060  14 04 03 05 03 06 03 08  07 08 04 08 05 08 06 04  |................|
00000070  01 05 01 06 01 ff 01 00  01 00 00 0a 00 0a 00 08  |................|
00000080  00 1d 00 17 00 18 00 19  00 0b 00 02 01 00 00 17  |................|
00000090  00 00                                             |..|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
193.163.125.122AS211298 Driftnet LtdGBDTLS22026-10-06 07:37

Latest datagrams