UDP traffic
Datagrams matching port:5074 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
Traffic by type
Other services
3 datagrams from 2 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest SIP datagram, to 5074/udp
INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 172.110.223.200:6438;branch=z9hG4bK-1273609695;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=63303033373639323133643201393430373530393534
Accept: application/sdp
User-Agent: friendly-scanner
To: "sipvicious"<sip:100@1.1.1.1>
payload bytes
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|
| 172.110.223.200 | AS23470 ReliableSite.Net LLC | HK | SIP | 2 | 2026-10-06 14:32 |
| 193.111.198.244 | AS24961 WIIT AG | DE | Redis | 1 | 2026-10-05 16:28 |
Latest datagrams
2026-10-06 14:32:55172.110.223.200to 5074/udpSIPHK INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 172.110.223.200:6438;branch=z9hG4bK-1273609695;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=63303033373639323133643201393430373
payload bytes
2026-10-06 12:53:44172.110.223.200to 5074/udpSIPHK INVITE sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 172.110.223.200:5118;branch=z9hG4bK-1827599618;rport
Content-Length: 0
From: "sipvicious"<sip:100@1.1.1.1>;tag=62396534353163393133643201323031393
payload bytes
2026-10-05 16:28:24193.111.198.244to 5074/udpRedisDE INFO sip:100@<HONEYPOT> SIP/2.0
Via: SIP/2.0/UDP 127.0.0.1:5061;branch=z9hG4bK1e676fc0
To: <sip:100@1.1.1.1>
From: <sip:100@1.1.1.1>;tag=d646511f
Call-ID: e4262af2caa232e5
CSeq: 1 INFO
Contact:
payload bytes