UDP 49192
Synopsis
- UDP 49192 is not assigned to a fixed service; it falls in the Dynamic/Private range and is widely used as an ephemeral source port.
- On Microsoft Windows Vista/Server 2008 and later, you’ll commonly see UDP 49192 as the source port for the DNS Client (svchost.exe/Dnscache) when querying resolvers (dest UDP 53).
- The same Windows hosts often use it as the source port for Windows Time (W32Time) NTP requests to servers on UDP 123.
- Web browsers and apps using QUIC or WebRTC—such as Google Chrome, Microsoft Edge, and Firefox—frequently select UDP 49192 as the local/source port when talking to QUIC servers (UDP 443) or STUN/TURN (UDP 3478/5349).
- On Linux and macOS, system resolvers (systemd-resolved, mDNSResponder) and NTP clients (systemd-timesyncd, chronyd, ntpd) also select ports in this range, so UDP 49192 commonly appears as their source port.
- Collaboration apps that use WebRTC (Microsoft Teams, Google Meet, Zoom) similarly originate media or STUN traffic from ephemeral ports, including UDP 49192.
- There is no widely recognized malware or exploit specifically tied to UDP 49192; its appearance usually reflects normal outbound client traffic.
Observed activity
Last 30 days
Detailed chart