UDP traffic
Datagrams matching ip:38.99.239.208 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
4
Datagrams
1
Source addresses
1
Networks
1
Countries
4
Destination ports
Traffic by type
Unrecognised
4 datagrams from 1 sourceDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 8083/udp
payload bytes
00000000 3b 2e 13 24 35 4d 40 1b 4b 45 4b 24 6a 7d 74 |;..$5M@.KEK$j}t|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| mDNS | 5353/udp | 1 | 1 | 2 to 10 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 38.99.239.208 | AS398991 X99 | US | Unrecognised | 4 | 2026-10-06 14:36 |
Latest datagrams
payload bytes
00000000 3b 2e 13 24 35 4d 40 1b 4b 45 4b 24 6a 7d 74 |;..$5M@.KEK$j}t|
payload bytes
00000000 36 2e 18 6e 45 3b 09 4c 5e 7b 77 38 3a 4e 31 2d |6..nE;.L^{w8:N1-| 00000010 37 2c 37 09 42 03 40 3b 49 15 72 50 1a 6b 5b 50 |7,7.B.@;I.rP.k[P| 00000020 6e 74 3e 33 2f 47 7f 0d 42 76 45 7c 44 f7 95 |nt>3/G..BvE|D..|payload bytes
00000000 3a 2e 08 14 51 0c 67 7e 2f 21 14 44 06 59 7c 25 |:...Q.g~/!.D.Y|%| 00000010 11 35 01 93 9e |.5...|
payload bytes
00000000 6f 2e 19 5c 1b 2d 3a 65 6a 90 f1 |o..\.-:ej..|