HoneyLabs

UDP traffic

Datagrams matching ip:47.84.101.219 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

33

Datagrams

1

Source addresses

1

Networks

1

Countries

28

Destination ports

Traffic by type

Service queries

9 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 520/udp

·D·

payload bytes
00000000  01 01 00 00 00 02 00 00  44 00 00 00 00 00 00 00  |........D.......|
00000010  00 00 00 00 00 00 00 0f                           |........|

Other services

4 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest HTTP datagram, to 30312/udp

payload bytes
00000000  47 45 54 20 2f 47 61 72  64 20 48 54 54 50 2f 31  |GET /Gard HTTP/1|
00000010  2e 30 0d 0a 0d 0a                                 |.0....|

Unrecognised

20 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 1701/udp

·u· · ·albatross.dev.hsd.com.au·Microsoft· · ·

payload bytes
00000000  c8 02 00 75 00 00 00 00  00 00 00 00 80 08 00 00  |...u............|
00000010  00 00 00 01 80 08 00 00  00 02 01 00 80 0a 00 00  |................|
00000020  00 03 00 00 00 01 80 0a  00 00 00 04 00 00 00 00  |................|
00000030  00 08 00 00 00 06 05 00  80 1e 00 00 00 07 61 6c  |..............al|
00000040  62 61 74 72 6f 73 73 2e  64 65 76 2e 68 73 64 2e  |batross.dev.hsd.|
00000050  63 6f 6d 2e 61 75 00 0f  00 00 00 08 4d 69 63 72  |com.au......Micr|
00000060  6f 73 6f 66 74 80 08 00  00 00 09 00 02 80 08 00  |osoft...........|
00000070  00 00 0a 00 08                                    |.....|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS520/udp +13128 to 54
SNMPv2161/udp316.3
TFTP69/udp1160
SSDP8888/udp1130.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
47.84.101.219AS45102 Alibaba (US) Technology Co., Ltd.SGUnrecognised332026-10-06 07:47

Latest datagrams