UDP 49192

ProtocolUDP
Port49192
Labels

Synopsis

  • UDP 49192 is not assigned to a fixed service; it falls in the Dynamic/Private range and is widely used as an ephemeral source port.
  • On Microsoft Windows Vista/Server 2008 and later, you’ll commonly see UDP 49192 as the source port for the DNS Client (svchost.exe/Dnscache) when querying resolvers (dest UDP 53).
  • The same Windows hosts often use it as the source port for Windows Time (W32Time) NTP requests to servers on UDP 123.
  • Web browsers and apps using QUIC or WebRTC—such as Google Chrome, Microsoft Edge, and Firefox—frequently select UDP 49192 as the local/source port when talking to QUIC servers (UDP 443) or STUN/TURN (UDP 3478/5349).
  • On Linux and macOS, system resolvers (systemd-resolved, mDNSResponder) and NTP clients (systemd-timesyncd, chronyd, ntpd) also select ports in this range, so UDP 49192 commonly appears as their source port.
  • Collaboration apps that use WebRTC (Microsoft Teams, Google Meet, Zoom) similarly originate media or STUN traffic from ephemeral ports, including UDP 49192.
  • There is no widely recognized malware or exploit specifically tied to UDP 49192; its appearance usually reflects normal outbound client traffic.

Observed activity

Last 30 days Detailed chart

More information