UDP traffic
Datagrams matching ip:5.39.125.103 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Source addresses (unverified)
| Address | Network | Cc | Datagrams | Last seen (UTC) |
|---|
| 5.39.125.103 | AS16276 OVH SAS | FR | 5 | 2026-10-05 16:23 |
Latest datagrams
2026-10-05 16:23:055.39.125.103to 48769/udpsipFR INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 5.39.125.103:5061;branch=z9hG4bK-856909545;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=313735653235653362653831013933303333353
payload bytes
2026-10-05 16:23:055.39.125.103to 49930/udpsipFR INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 5.39.125.103:5061;branch=z9hG4bK-802416268;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=313735653235653363333061013336303239393
payload bytes
2026-10-05 16:23:055.39.125.103to 50307/udpsipFR INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 5.39.125.103:5061;branch=z9hG4bK-2993799883;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=31373565323565336334383301313435343932
payload bytes
2026-10-05 16:23:055.39.125.103to 6496/udpsipFR INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 5.39.125.103:5061;branch=z9hG4bK-3059551696;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=31373565323565333139363001343139353732
payload bytes
2026-10-05 16:23:055.39.125.103to 50051/udpsipFR INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 5.39.125.103:5061;branch=z9hG4bK-3260274920;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=31373565323565336333383301323939303936
payload bytes