UDP traffic
Datagrams matching ip:37.112.63.117 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
2
Datagrams
1
Source addresses
1
Networks
1
Countries
2
Destination ports
Traffic by type
Unrecognised
2 datagrams from 1 sourceDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 5353/udp
payload bytes
00000000 74 2e 65 e3 ce |t.e..|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| mDNS | 5353/udp | 1 | 1 | 2 to 10 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 37.112.63.117 | AS57044 JSC ER-Telecom Holding | RU | Unrecognised | 2 | 2026-10-06 16:52 |
Latest datagrams
payload bytes
00000000 74 2e 65 e3 ce |t.e..|
payload bytes
00000000 0a 2e 49 04 2c 64 5a 73 26 5f 25 15 1c 76 33 55 |..I.,dZs&_%..v3U| 00000010 38 16 19 24 48 45 3e 32 02 79 03 2b 10 2d 74 1a |8..$HE>2.y.+.-t.| 00000020 07 3d 1e 33 21 79 27 47 58 4c 5c 75 43 0f 4a 7b |.=.3!y'GXL\uC.J{| 00000030 25 63 1f 6d 28 5e 1f 2b 57 22 56 67 50 4a 02 57 |%c.m(^.+W"VgPJ.W| 00000040 08 20 0b 29 19 32 71 72 7e 4d 67 41 5d 31 3c 91 |. .).2qr~MgA]1<.| 00000050 6c |l|