UDP traffic
Datagrams matching asn:6147 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
1.8K
Datagrams
20
Source addresses
1
Networks
1
Countries
2
Destination ports
Traffic by type
Service queries
2 datagrams from 1 sourceRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 57 f1 e0 3d ba 55 3b ee ad f8 ab f3 ff b4 b8 f0 |W..=.U;.........| 00000010 f6 89 e8 ca 94 83 4a fe 60 62 88 52 82 3b a2 67 |......J.`b.R.;.g| 00000020 b9 a9 8b e9 3f c1 77 43 53 30 fd 52 a5 6f f5 24 |....?.wCS0.R.o.$| 00000030 e3 cc 87 90 f5 99 04 6d ae 43 c0 d6 94 96 c7 59 |.......m.C.....Y| 00000040 9b a9 89 f7 ae 4d 0b be f2 b4 02 6a 10 fc 14 0f |.....M.....j....| 00000050 18 49 6b b5 26 04 e9 51 cd 8f 33 2e 67 02 6f 86 |.Ik.&..Q..3.g.o.| 00000060 3b b8 a3 69 1d 49 72 70 39 ed 8d c2 35 b3 0f 3c |;..i.Irp9...5..<| 00000070 ef b6 19 48 50 24 c1 aa 14 f0 88 07 cb 7d 5f 46 |...HP$.......}_F| 00000080 21 15 74 c3 bb 4a 34 60 f9 1e 7c 20 18 8e 70 9d |!.t..J4`..| ..p.| 00000090 8a 5d ce fe 7a b1 6d 3c d8 eb 26 fc 0a ba 3f e5 |.]..z.m<..&...?.| 000000a0 2a 89 91 69 03 03 26 38 f4 57 95 f3 66 4c 62 eb |*..i..&8.W..fLb.| 000000b0 f9 50 5f 0e 2a 74 69 06 e4 a9 1a 5f 1d df e2 a6 |.P_.*ti...._....| 000000c0 a0 8b ce 52 f7 6d 4b 1f 73 b2 94 95 eb 8d 3e 25 |...R.mK.s.....>%| 000000d0 67 91 8b 03 34 60 eb 47 90 45 dc 77 55 cf 5c a6 |g...4`.G.E.wU.\.| 000000e0 50 72 03 f9 84 47 f5 e5 6f 6e 90 70 4f 21 f6 30 |Pr...G..on.pO!.0| 000000f0 f3 44 85 d2 40 f0 03 9d 99 16 13 6e 4d be 6e ef |.D..@......nM.n.|
Peer-to-peer
1,767 datagrams from 19 sourcesFile-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| DNS | 53/udp | 2 | 1 | 28 to 54 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 190.43.149.108 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 507 | 2026-10-10 02:49 |
| 201.230.200.72 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 261 | 2026-10-11 05:00 |
| 181.66.151.13 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 194 | 2026-10-10 23:39 |
| 190.237.0.152 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 180 | 2026-10-10 02:41 |
| 190.235.116.179 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 170 | 2026-10-09 20:04 |
| 190.237.1.204 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 129 | 2026-10-06 21:33 |
| 200.48.38.104 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 100 | 2026-10-10 21:18 |
| 201.230.249.121 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 68 | 2026-10-10 21:12 |
| 181.66.128.26 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 55 | 2026-10-11 01:49 |
| 201.230.169.154 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 25 | 2026-10-10 02:51 |
| 181.66.181.15 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 17 | 2026-10-10 02:28 |
| 190.238.118.130 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 16 | 2026-10-09 03:04 |
| 190.43.149.251 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 10 | 2026-10-10 23:08 |
| 181.64.13.11 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 10 | 2026-10-08 02:47 |
| 201.240.171.166 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 10 | 2026-10-05 21:43 |
| 190.237.8.237 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 6 | 2026-10-10 22:59 |
| 181.65.36.54 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 4 | 2026-10-07 01:58 |
| 181.66.151.196 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 4 | 2026-10-09 19:38 |
| 190.236.206.82 | AS6147 INTEGRATEL PERU S.A.A. | PE | DNS | 2 | 2026-10-10 23:04 |
| 190.236.179.192 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 1 | 2026-10-09 13:20 |
Latest datagrams
payload bytes
00000000 41 00 b5 53 b3 51 08 70 00 00 00 00 00 10 00 00 |A..S.Q.p........| 00000010 1c 32 00 00 |.2..|
payload bytes
00000000 41 00 b5 53 b2 f3 a5 0a 00 00 00 00 00 10 00 00 |A..S............| 00000010 1c 32 00 00 |.2..|
payload bytes
00000000 41 00 b5 53 b2 c2 66 b5 00 00 00 00 00 10 00 00 |A..S..f.........| 00000010 1c 32 00 00 |.2..|
payload bytes
00000000 41 00 c9 ec a2 cc 64 ca 00 00 00 00 00 10 00 00 |A.....d.........| 00000010 49 cc 00 00 |I...|
payload bytes
00000000 41 00 c9 ec a2 70 88 df 00 00 00 00 00 10 00 00 |A....p..........| 00000010 49 cc 00 00 |I...|
payload bytes
00000000 41 00 c9 ec a2 40 4c 4f 00 00 00 00 00 10 00 00 |A....@LO........| 00000010 49 cc 00 00 |I...|
payload bytes
00000000 41 00 7a 1f 91 77 a8 08 00 00 00 00 00 10 00 00 |A.z..w..........| 00000010 68 3f 00 00 |h?..|
payload bytes
00000000 41 00 7a 1f 91 1b 9f f4 00 00 00 00 00 10 00 00 |A.z.............| 00000010 68 3f 00 00 |h?..|
payload bytes
00000000 41 00 7a 1f 90 e7 9c d1 00 00 00 00 00 10 00 00 |A.z.............| 00000010 68 3f 00 00 |h?..|
payload bytes
00000000 41 00 b2 82 8b d9 33 16 00 00 00 00 00 10 00 00 |A.....3.........| 00000010 e0 21 00 00 |.!..|
payload bytes
00000000 41 00 b2 82 8b 7d 27 cf 00 00 00 00 00 10 00 00 |A....}'.........| 00000010 e0 21 00 00 |.!..|
payload bytes
00000000 41 00 b2 82 8b 4c cd 80 00 00 00 00 00 10 00 00 |A....L..........| 00000010 e0 21 00 00 |.!..|
payload bytes
00000000 41 00 20 84 85 2c d2 16 00 00 00 00 00 10 00 00 |A. ..,..........| 00000010 ba 2e 00 00 |....|
payload bytes
00000000 41 00 20 84 84 d0 05 09 00 00 00 00 00 10 00 00 |A. .............| 00000010 ba 2e 00 00 |....|
payload bytes
00000000 41 00 20 84 84 9f 90 d7 00 00 00 00 00 10 00 00 |A. .............| 00000010 ba 2e 00 00 |....|