HoneyLabs

UDP traffic

Datagrams matching port:37020 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

Your plan searches up to 7d, so 30d was shortened. Plans

12

Datagrams

3

Source addresses

3

Networks

3

Countries

1

Destination ports

Traffic by type

Service queries

6 datagrams from 2 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest SOAP datagram, to 37020/udp

<?xml version="1.0" encoding="utf-8"?><Probe><Uuid>a9787e55-502c-4659-970a-dcaa2be5f068</Uuid><Types>inquiry</Types></Probe>

payload bytes
00000000  3c 3f 78 6d 6c 20 76 65  72 73 69 6f 6e 3d 22 31  |<?xml version="1|
00000010  2e 30 22 20 65 6e 63 6f  64 69 6e 67 3d 22 75 74  |.0" encoding="ut|
00000020  66 2d 38 22 3f 3e 3c 50  72 6f 62 65 3e 3c 55 75  |f-8"?><Probe><Uu|
00000030  69 64 3e 61 39 37 38 37  65 35 35 2d 35 30 32 63  |id>a9787e55-502c|
00000040  2d 34 36 35 39 2d 39 37  30 61 2d 64 63 61 61 32  |-4659-970a-dcaa2|
00000050  62 65 35 66 30 36 38 3c  2f 55 75 69 64 3e 3c 54  |be5f068</Uuid><T|
00000060  79 70 65 73 3e 69 6e 71  75 69 72 79 3c 2f 54 79  |ypes>inquiry</Ty|
00000070  70 65 73 3e 3c 2f 50 72  6f 62 65 3e              |pes></Probe>|

Unrecognised

6 datagrams from 1 source

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 37020/udp

<?><Probe><Types>inquiry</Types></Probe>

payload bytes
00000000  3c 3f 3e 3c 50 72 6f 62  65 3e 3c 54 79 70 65 73  |<?><Probe><Types|
00000010  3e 69 6e 71 75 69 72 79  3c 2f 54 79 70 65 73 3e  |>inquiry</Types>|
00000020  3c 2f 50 72 6f 62 65 3e                           |</Probe>|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
141.98.83.48AS209588 Flyservers S.A.PAUnrecognised62026-10-06 00:35
16.5.0.234AS401661 EMBNEX, LLCBRSOAP52026-10-05 19:24
193.163.125.165AS211298 Driftnet LtdGBSOAP12026-10-05 21:51

Latest datagrams