HoneyLabs

UDP traffic

Datagrams matching ip:91.230.168.222 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

4

Datagrams

1

Source addresses

1

Networks

1

Countries

4

Destination ports

Traffic by type

Service queries

2 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest CLDAP datagram, to 389/udp

0·-·c·$· · ·d·objectClass0·

payload bytes
00000000  30 84 00 00 00 2d 02 01  07 63 84 00 00 00 24 04  |0....-...c....$.|
00000010  00 0a 01 00 0a 01 00 02  01 00 02 01 64 01 01 00  |............d...|
00000020  87 0b 6f 62 6a 65 63 74  43 6c 61 73 73 30 84 00  |..objectClass0..|
00000030  00 00 00                                          |...|

Other services

1 datagrams from 1 source

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SIP datagram, to 5060/udp

OPTIONS sip:nm SIP/2.0 Via: SIP/2.0/UDP nm;branch=foo;rport From: <sip:nm@nm>;tag=root To: <sip:nm2@nm2> Call-ID: 50000 CSeq: 42 OPTIONS Max-Forwards: 70 Content-Length: 0 Contact: <sip:nm@nm> Accept: application/sdp

payload bytes
00000000  4f 50 54 49 4f 4e 53 20  73 69 70 3a 6e 6d 20 53  |OPTIONS sip:nm S|
00000010  49 50 2f 32 2e 30 0d 0a  56 69 61 3a 20 53 49 50  |IP/2.0..Via: SIP|
00000020  2f 32 2e 30 2f 55 44 50  20 6e 6d 3b 62 72 61 6e  |/2.0/UDP nm;bran|
00000030  63 68 3d 66 6f 6f 3b 72  70 6f 72 74 0d 0a 46 72  |ch=foo;rport..Fr|
00000040  6f 6d 3a 20 3c 73 69 70  3a 6e 6d 40 6e 6d 3e 3b  |om: <sip:nm@nm>;|
00000050  74 61 67 3d 72 6f 6f 74  0d 0a 54 6f 3a 20 3c 73  |tag=root..To: <s|
00000060  69 70 3a 6e 6d 32 40 6e  6d 32 3e 0d 0a 43 61 6c  |ip:nm2@nm2>..Cal|
00000070  6c 2d 49 44 3a 20 35 30  30 30 30 0d 0a 43 53 65  |l-ID: 50000..CSe|
00000080  71 3a 20 34 32 20 4f 50  54 49 4f 4e 53 0d 0a 4d  |q: 42 OPTIONS..M|
00000090  61 78 2d 46 6f 72 77 61  72 64 73 3a 20 37 30 0d  |ax-Forwards: 70.|
000000a0  0a 43 6f 6e 74 65 6e 74  2d 4c 65 6e 67 74 68 3a  |.Content-Length:|
000000b0  20 30 0d 0a 43 6f 6e 74  61 63 74 3a 20 3c 73 69  | 0..Contact: <si|
000000c0  70 3a 6e 6d 40 6e 6d 3e  0d 0a 41 63 63 65 70 74  |p:nm@nm>..Accept|
000000d0  3a 20 61 70 70 6c 69 63  61 74 69 6f 6e 2f 73 64  |: application/sd|
000000e0  70 0d 0a 0d 0a                                    |p....|

Unrecognised

1 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 2363/udp

DIGI·

payload bytes
00000000  44 49 47 49 00 01 00 06  ff ff ff ff ff ff        |DIGI..........|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
CLDAP389/udp1156 to 70
SSDP1900/udp1130.8

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
91.230.168.222AS213412 ONYPHE SASUSUnrecognised42026-10-06 21:54

Latest datagrams