UDP traffic
Datagrams matching country:JP sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
174
Datagrams
16
Source addresses
8
Networks
1
Countries
13
Destination ports
Traffic by type
Service queries
26 datagrams from 5 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest NTP datagram, to 123/udp
payload bytes
00000000 e3 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
Other services
1 datagrams from 1 sourceFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest SKYPECALL datagram, to 3671/udp
payload bytes
00000000 06 10 02 05 00 1a 08 01 00 00 00 00 00 00 08 01 |................| 00000010 00 00 00 00 00 00 04 04 02 00 |..........|
Unrecognised
138 datagrams from 10 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 500/udp
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
Peer-to-peer
9 datagrams from 1 sourceFile-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
DNS questions
DNS record types
- A10
Networks
- AS63949 Akamai Connected Cloud from 7 sources146
- AS137409 GSL Networks Pty LTD from 1 source9
- AS63199 CDS Global Cloud Co., Ltd from 1 source6
- AS45102 Alibaba (US) Technology Co., Ltd. from 3 sources6
- AS10010 TOKAI Communications Corporation from 1 source3
- AS141995 Contabo Asia Private Limited from 1 source2
- AS2514 NTT PC Communications, Inc. from 1 source1
- AS4685 Asahi Net from 1 source1
Countries
- JP Japan174
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 139.162.88.198 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 52 | 2026-10-10 19:24 |
| 139.162.116.160 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 48 | 2026-10-11 01:55 |
| 139.162.120.104 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 16 | 2026-10-10 20:10 |
| 139.162.66.65 | AS63949 Akamai Connected Cloud | JP | DNS | 10 | 2026-10-10 18:01 |
| 187.15.134.130 | AS137409 GSL Networks Pty LTD | JP | BitTorrent | 9 | 2026-10-10 10:19 |
| 139.162.109.245 | AS63949 Akamai Connected Cloud | JP | NTP | 8 | 2026-10-09 15:37 |
| 139.162.113.92 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 8 | 2026-10-10 18:42 |
| 164.52.24.182 | AS63199 CDS Global Cloud Co., Ltd | JP | Unrecognised | 6 | 2026-10-08 13:44 |
| 139.162.116.104 | AS63949 Akamai Connected Cloud | JP | Unrecognised | 4 | 2026-10-05 19:11 |
| 47.74.5.117 | AS45102 Alibaba (US) Technology Co., Ltd. | JP | Unrecognised | 4 | 2026-10-06 00:41 |
| 117.104.10.130 | AS10010 TOKAI Communications Corporation | JP | NetBIOS | 3 | 2026-10-10 12:35 |
| 84.247.157.60 | AS141995 Contabo Asia Private Limited | JP | Unrecognised | 2 | 2026-10-10 06:56 |
| 8.216.9.247 | AS45102 Alibaba (US) Technology Co., Ltd. | JP | SKYPECALL | 1 | 2026-10-05 21:45 |
| 117.102.211.7 | AS2514 NTT PC Communications, Inc. | JP | NetBIOS | 1 | 2026-10-09 08:32 |
| 118.243.254.87 | AS4685 Asahi Net | JP | Unrecognised | 1 | 2026-10-06 13:25 |
| 8.216.8.122 | AS45102 Alibaba (US) Technology Co., Ltd. | JP | Unrecognised | 1 | 2026-10-07 13:26 |
Latest datagrams
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 38 12 12 12 12 12 12 12 12 00 00 00 00 00 38 b1 |8.............8.| 00000010 26 de |&.|
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 38 00 00 00 00 00 00 00 00 00 00 00 01 |8............|
payload bytes
00000000 38 00 00 00 00 00 00 00 00 00 00 00 01 |8............|
payload bytes
00000000 ff ff ff ff 54 53 6f 75 72 63 65 20 45 6e 67 69 |....TSource Engi| 00000010 6e 65 20 51 75 65 72 79 00 |ne Query.|
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 38 00 00 00 00 00 00 00 00 00 00 00 01 |8............|
payload bytes
00000000 80 0a 01 00 00 01 00 00 00 00 00 00 06 69 6e 61 |.............ina| 00000010 6e 69 73 10 61 73 65 72 74 64 6e 73 72 65 73 65 |nis.asertdnsrese| 00000020 61 72 63 68 03 63 6f 6d 00 00 01 00 01 |arch.com.....|
payload bytes
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000010 21 20 22 08 00 00 00 00 00 00 00 1c |! ".........|
payload bytes
00000000 38 00 00 00 00 00 00 00 00 00 00 00 01 |8............|
payload bytes
00000000 ff ff ff ff 54 53 6f 75 72 63 65 20 45 6e 67 69 |....TSource Engi| 00000010 6e 65 20 51 75 65 72 79 00 |ne Query.|
payload bytes
00000000 a2 48 00 00 00 01 00 00 00 00 00 00 20 43 4b 41 |.H.......... CKA| 00000010 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 |AAAAAAAAAAAAAAAA| 00000020 41 41 41 41 41 41 41 41 41 41 41 41 41 00 00 21 |AAAAAAAAAAAAA..!| 00000030 00 01 |..|
payload bytes
00000000 41 00 5f 2e f7 3c 86 b6 00 00 00 00 00 08 00 00 |A._..<..........| 00000010 48 31 00 00 |H1..|