HoneyLabs

UDP traffic

Datagrams matching ip:199.45.154.191 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

5

Datagrams

1

Source addresses

1

Networks

1

Countries

5

Destination ports

Traffic by type

Service queries

2 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 17184/udp

· ·UUUU·U·<·

payload bytes
00000000  1a 09 fa ba 00 00 00 00  00 00 00 02 55 55 55 55  |............UUUU|
00000010  00 00 00 01 00 00 00 01  00 00 00 00 00 00 00 00  |................|
00000020  00 00 00 00 00 00 00 00  ff ff 55 12 00 00 00 3c  |..........U....<|
00000030  00 00 00 01 00 00 00 02  00 00 00 00 00 00 00 00  |................|

Other services

1 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5061/udp

OPTIONS sip:censysinspect@censys.io SIP/2.0 To: <sip:test.echo@sip5060.net> From: Censys <sip:censysinspect@censys.io> CSeq: 1 OPTIONS Call-ID: a84b4c76e66710 Max-Forwards: 70 Via: SIP/2.0/UDP 127.0.0.1 Accept: application/sdp Content-Length: 0

payload bytes
00000000  4f 50 54 49 4f 4e 53 20  73 69 70 3a 63 65 6e 73  |OPTIONS sip:cens|
00000010  79 73 69 6e 73 70 65 63  74 40 63 65 6e 73 79 73  |ysinspect@censys|
00000020  2e 69 6f 20 53 49 50 2f  32 2e 30 0d 0a 54 6f 3a  |.io SIP/2.0..To:|
00000030  20 3c 73 69 70 3a 74 65  73 74 2e 65 63 68 6f 40  | <sip:test.echo@|
00000040  73 69 70 35 30 36 30 2e  6e 65 74 3e 0d 0a 46 72  |sip5060.net>..Fr|
00000050  6f 6d 3a 20 43 65 6e 73  79 73 20 3c 73 69 70 3a  |om: Censys <sip:|
00000060  63 65 6e 73 79 73 69 6e  73 70 65 63 74 40 63 65  |censysinspect@ce|
00000070  6e 73 79 73 2e 69 6f 3e  0d 0a 43 53 65 71 3a 20  |nsys.io>..CSeq: |
00000080  31 20 4f 50 54 49 4f 4e  53 0d 0a 43 61 6c 6c 2d  |1 OPTIONS..Call-|
00000090  49 44 3a 20 61 38 34 62  34 63 37 36 65 36 36 37  |ID: a84b4c76e667|
000000a0  31 30 0d 0a 4d 61 78 2d  46 6f 72 77 61 72 64 73  |10..Max-Forwards|
000000b0  3a 20 37 30 0d 0a 56 69  61 3a 20 53 49 50 2f 32  |: 70..Via: SIP/2|
000000c0  2e 30 2f 55 44 50 20 31  32 37 2e 30 2e 30 2e 31  |.0/UDP 127.0.0.1|
000000d0  0d 0a 41 63 63 65 70 74  3a 20 61 70 70 6c 69 63  |..Accept: applic|
000000e0  61 74 69 6f 6e 2f 73 64  70 0d 0a 43 6f 6e 74 65  |ation/sdp..Conte|
000000f0  6e 74 2d 4c 65 6e 67 74  68 3a 20 30 0d 0a 0d 0a  |nt-Length: 0....|

Unrecognised

2 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 47809/udp

· ·?·K

payload bytes
00000000  81 0a 00 11 01 04 00 05  01 0c 0c 02 3f ff ff 19  |............?...|
00000010  4b                                                |K|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS17184/udp1128 to 54
SSDP1900/udp1130.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
199.45.154.191AS398722 Censys, Inc.USUnrecognised52026-10-06 18:42

Latest datagrams