UDP traffic
Datagrams matching ip:66.132.172.228 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Your plan searches up to 7d, so 30d was shortened. Plans
4
Datagrams
1
Source addresses
1
Networks
1
Countries
4
Destination ports
Traffic by type
Service queries
2 datagrams from 1 sourceRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 70 9a 01 00 00 01 00 00 00 00 00 01 02 69 70 09 |p............ip.| 00000010 70 61 72 72 6f 74 64 6e 73 03 63 6f 6d 00 00 01 |parrotdns.com...| 00000020 00 01 00 00 29 02 00 00 00 80 00 00 00 |....)........|
Unrecognised
2 datagrams from 1 sourceDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 2361/udp
payload bytes
00000000 44 49 47 49 00 01 00 06 ff ff ff ff ff ff |DIGI..........|
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| DNS | 17186/udp +1 | 2 | 1 | 28 to 54 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
DNS questions
DNS record types
- A1
Networks
- AS398324 Censys, Inc. from 1 source4
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 66.132.172.228 | AS398324 Censys, Inc. | US | DNS | 4 | 2026-10-06 10:33 |
Latest datagrams
payload bytes
00000000 70 9a 01 00 00 01 00 00 00 00 00 01 02 69 70 09 |p............ip.| 00000010 70 61 72 72 6f 74 64 6e 73 03 63 6f 6d 00 00 01 |parrotdns.com...| 00000020 00 01 00 00 29 02 00 00 00 80 00 00 00 |....)........|
payload bytes
00000000 44 49 47 49 00 01 00 06 ff ff ff ff ff ff |DIGI..........|
payload bytes
00000000 1a 09 fa ba 00 00 00 00 00 00 00 02 55 55 55 55 |............UUUU| 00000010 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 |................| 00000020 00 00 00 00 00 00 00 00 ff ff 55 12 00 00 00 3c |..........U....<| 00000030 00 00 00 01 00 00 00 02 00 00 00 00 00 00 00 00 |................|
payload bytes
00000000 4d 65 82 21 07 fc fd 52 00 00 00 00 00 00 00 00 |Me.!...R........| 00000010 01 10 02 00 00 00 00 00 00 00 01 50 00 00 01 34 |...........P...4| 00000020 00 00 00 01 00 00 00 01 00 00 01 28 01 01 00 08 |...........(....| 00000030 03 00 00 24 01 01 00 00 80 01 00 05 80 02 00 02 |...$............| 00000040 80 03 00 01 80 04 00 01 80 0b 00 01 00 0c 00 04 |................| 00000050 00 00 01 00 03 00 00 24 02 01 00 00 80 01 00 05 |.......$........| 00000060 80 02 00 02 80 03 00 01 80 04 00 02 80 0b 00 01 |................| 00000070 00 0c 00 04 00 00 01 00 03 00 00 24 03 01 00 00 |...........$....| 00000080 80 01 00 05 80 02 00 01 80 03 00 01 80 04 00 01 |................| 00000090 80 0b 00 01 00 0c 00 04 00 00 01 00 03 00 00 24 |...............$| 000000a0 04 01 00 00 80 01 00 05 80 02 00 01 80 03 00 01 |................| 000000b0 80 04 00 02 80 0b 00 01 00 0c 00 04 00 00 01 00 |................| 000000c0 03 00 00 24 05 01 00 00 80 01 00 01 80 02 00 01 |...$............| 000000d0 80 03 00 01 80 04 00 01 80 0b 00 01 00 0c 00 04 |................| 000000e0 00 00 01 00 03 00 00 24 06 01 00 00 80 01 00 01 |.......$........| 000000f0 80 02 00 01 80 03 00 01 80 04 00 02 80 0b 00 01 |................| ... 336 bytes shown in part