HoneyLabs

UDP traffic

Datagrams matching ip:66.132.186.207 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

3

Datagrams

1

Source addresses

1

Networks

1

Countries

3

Destination ports

Traffic by type

Service queries

1 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest SOAP datagram, to 3702/udp

<?xml version="1.0" encoding="utf-8"?> <soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope" xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:wsd="http://schemas.xmlsoap.org/ws/2005/04/discovery" xmlns:wsdp="http://schemas.xmlsoap.org/ws/2006/02/devprof"> <soap:Header

payload bytes
00000000  3c 3f 78 6d 6c 20 76 65  72 73 69 6f 6e 3d 22 31  |<?xml version="1|
00000010  2e 30 22 20 65 6e 63 6f  64 69 6e 67 3d 22 75 74  |.0" encoding="ut|
00000020  66 2d 38 22 3f 3e 0a 3c  73 6f 61 70 3a 45 6e 76  |f-8"?>.<soap:Env|
00000030  65 6c 6f 70 65 20 78 6d  6c 6e 73 3a 73 6f 61 70  |elope xmlns:soap|
00000040  3d 22 68 74 74 70 3a 2f  2f 77 77 77 2e 77 33 2e  |="http://www.w3.|
00000050  6f 72 67 2f 32 30 30 33  2f 30 35 2f 73 6f 61 70  |org/2003/05/soap|
00000060  2d 65 6e 76 65 6c 6f 70  65 22 20 78 6d 6c 6e 73  |-envelope" xmlns|
00000070  3a 77 73 61 3d 22 68 74  74 70 3a 2f 2f 73 63 68  |:wsa="http://sch|
00000080  65 6d 61 73 2e 78 6d 6c  73 6f 61 70 2e 6f 72 67  |emas.xmlsoap.org|
00000090  2f 77 73 2f 32 30 30 34  2f 30 38 2f 61 64 64 72  |/ws/2004/08/addr|
000000a0  65 73 73 69 6e 67 22 20  78 6d 6c 6e 73 3a 77 73  |essing" xmlns:ws|
000000b0  64 3d 22 68 74 74 70 3a  2f 2f 73 63 68 65 6d 61  |d="http://schema|
000000c0  73 2e 78 6d 6c 73 6f 61  70 2e 6f 72 67 2f 77 73  |s.xmlsoap.org/ws|
000000d0  2f 32 30 30 35 2f 30 34  2f 64 69 73 63 6f 76 65  |/2005/04/discove|
000000e0  72 79 22 20 78 6d 6c 6e  73 3a 77 73 64 70 3d 22  |ry" xmlns:wsdp="|
000000f0  68 74 74 70 3a 2f 2f 73  63 68 65 6d 61 73 2e 78  |http://schemas.x|

Unrecognised

2 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 44818/udp

c·censys·

payload bytes
00000000  63 00 00 00 00 00 00 00  00 00 00 00 00 00 63 65  |c.............ce|
00000010  6e 73 79 73 00 00 00 00                           |nsys....|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
WS-Discovery3702/udp1110 to 500

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
66.132.186.207AS398324 Censys, Inc.USUnrecognised32026-10-06 16:46

Latest datagrams