HoneyLabs

UDP traffic

Datagrams matching qname:"CKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

17

Datagrams

7

Source addresses

6

Networks

4

Countries

2

Destination ports

Protocols

  • dns from 7 sources17

Destination ports

DNS questions

17 queries and 0 unsolicited answers. An answer nobody asked for means a resolver was given a forged source address.

DNS record types

Networks

Countries

Source addresses (unverified)

AddressNetworkCcDatagramsLast seen (UTC)
16.5.0.234AS401661 EMBNEX, LLCBR92026-10-05 15:55
62.210.90.215AS12876 Scaleway SASFR22026-10-05 16:54
146.88.241.80AS20052 Arbor Networks, Inc.US22026-10-05 14:18
146.88.240.27AS20052 Arbor Networks, Inc.US12026-10-05 13:05
137.184.210.250AS14061 DigitalOcean, LLCUS12026-10-05 13:49
66.132.172.242AS398324 Censys, Inc.US12026-10-05 12:50
185.36.81.23AS209605 UAB Host BalticLT12026-10-05 11:54

Latest datagrams