UDP traffic
Datagrams matching port:5069 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Traffic by type
Other services
3 datagrams from 2 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest SIP datagram, to 5069/udp
INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 172.110.223.200:6438;branch=z9hG4bK-3649717362;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=6330303337363932313363640131333835393535323031
Accept: application/sdp
User-Agent: friendly-scanner
To: "sipvicious"<sip:100@1.1.1.1
payload bytes
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|
| 172.110.223.200 | AS23470 ReliableSite.Net LLC | HK | SIP | 2 | 2026-10-06 14:32 |
| 193.111.198.244 | AS24961 WIIT AG | DE | Redis | 1 | 2026-10-05 16:28 |
Latest datagrams
2026-10-06 14:32:55172.110.223.200to 5069/udpSIPHK INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 172.110.223.200:6438;branch=z9hG4bK-3649717362;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=63303033373639323133636401313338353
payload bytes
2026-10-06 12:53:44172.110.223.200to 5069/udpSIPHK INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 172.110.223.200:5118;branch=z9hG4bK-4224789265;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=62396534353163393133636401333738373
payload bytes
2026-10-05 16:28:24193.111.198.244to 5069/udpRedisDE INFO sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 127.0.0.1:5061;branch=z9hG4bKc6b211b6
To: <sip:100@1.1.1.1>
From: <sip:100@1.1.1.1>;tag=1da7d815
Call-ID: d07ac496da39212
CSeq: 1 INFO
Contact: <
payload bytes