HoneyLabs

UDP traffic

Datagrams matching country:PE sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

8.2K

Datagrams

92

Source addresses

17

Networks

1

Countries

14

Destination ports

Traffic by type

Service queries

2 datagrams from 1 source

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest DNS datagram, to 53/udp

W·=·U;·ʔ·J·`b·R·;·g·?·wCS0·R·o·$·̇·m·C·֔·Y·M·j·Ik·&·Q͏3.g·o·;·i·Irp9·5·<·HP$·}_F!·tûJ4`·| ·p·]·z·m<·&· ·

payload bytes
00000000  57 f1 e0 3d ba 55 3b ee  ad f8 ab f3 ff b4 b8 f0  |W..=.U;.........|
00000010  f6 89 e8 ca 94 83 4a fe  60 62 88 52 82 3b a2 67  |......J.`b.R.;.g|
00000020  b9 a9 8b e9 3f c1 77 43  53 30 fd 52 a5 6f f5 24  |....?.wCS0.R.o.$|
00000030  e3 cc 87 90 f5 99 04 6d  ae 43 c0 d6 94 96 c7 59  |.......m.C.....Y|
00000040  9b a9 89 f7 ae 4d 0b be  f2 b4 02 6a 10 fc 14 0f  |.....M.....j....|
00000050  18 49 6b b5 26 04 e9 51  cd 8f 33 2e 67 02 6f 86  |.Ik.&..Q..3.g.o.|
00000060  3b b8 a3 69 1d 49 72 70  39 ed 8d c2 35 b3 0f 3c  |;..i.Irp9...5..<|
00000070  ef b6 19 48 50 24 c1 aa  14 f0 88 07 cb 7d 5f 46  |...HP$.......}_F|
00000080  21 15 74 c3 bb 4a 34 60  f9 1e 7c 20 18 8e 70 9d  |!.t..J4`..| ..p.|
00000090  8a 5d ce fe 7a b1 6d 3c  d8 eb 26 fc 0a ba 3f e5  |.]..z.m<..&...?.|
000000a0  2a 89 91 69 03 03 26 38  f4 57 95 f3 66 4c 62 eb  |*..i..&8.W..fLb.|
000000b0  f9 50 5f 0e 2a 74 69 06  e4 a9 1a 5f 1d df e2 a6  |.P_.*ti...._....|
000000c0  a0 8b ce 52 f7 6d 4b 1f  73 b2 94 95 eb 8d 3e 25  |...R.mK.s.....>%|
000000d0  67 91 8b 03 34 60 eb 47  90 45 dc 77 55 cf 5c a6  |g...4`.G.E.wU.\.|
000000e0  50 72 03 f9 84 47 f5 e5  6f 6e 90 70 4f 21 f6 30  |Pr...G..on.pO!.0|
000000f0  f3 44 85 d2 40 f0 03 9d  99 16 13 6e 4d be 6e ef  |.D..@......nM.n.|

Other services

6 datagrams from 3 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SOCKS5 datagram, to 16880/udp

·4Vx·

payload bytes
00000000  05 00 ff ff 00 fe fe fe  fe fd fd fd fd 12 34 56  |..............4V|
00000010  78 06 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |x...............|
00000020  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000030  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000040  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000050  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000060  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000070  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000080  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000a0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000b0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000c0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000d0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000e0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000f0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|

Unrecognised

6 datagrams from 6 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 11183/udp

·q·ԥ#$·4Vx·3,\·Zb

payload bytes
00000000  01 1e 71 b3 fb d4 a5 23  24 00 ff ff 00 fe fe fe  |..q....#$.......|
00000010  fe fd fd fd fd 12 34 56  78 14 33 2c 5c da eb 5a  |......4Vx.3,\..Z|
00000020  62                                                |b|

Peer-to-peer

8,197 datagrams from 82 sources

File-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
DNS53/udp2128 to 54

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
179.6.16.189AS12252 America Movil Peru S.A.C.PEBitTorrent9642026-10-11 03:15
179.6.0.117AS12252 America Movil Peru S.A.C.PEBitTorrent7592026-10-11 04:31
38.25.25.58AS265691 WI-NET TELECOM S.A.C.PEBitTorrent6752026-10-08 03:48
190.43.149.108AS6147 INTEGRATEL PERU S.A.A.PEBitTorrent5072026-10-10 02:49
38.25.8.41AS265691 WI-NET TELECOM S.A.C.PEBitTorrent4662026-10-11 03:54
179.6.3.87AS12252 America Movil Peru S.A.C.PEBitTorrent4192026-10-10 21:09
200.215.249.48AS269981 COMPUNETWORK S.A.C.PEBitTorrent4142026-10-10 21:11
38.255.109.186AS272836 CALA SERVICIOS INTEGRALES E.I.R.L.PEBitTorrent3462026-10-10 21:48
179.6.3.78AS12252 America Movil Peru S.A.C.PEBitTorrent3212026-10-09 20:47
179.6.15.158AS12252 America Movil Peru S.A.C.PEBitTorrent2872026-10-10 07:21
201.230.200.72AS6147 INTEGRATEL PERU S.A.A.PEBitTorrent2452026-10-10 21:12
38.25.83.145AS265691 WI-NET TELECOM S.A.C.PEBitTorrent2172026-10-11 04:27
38.250.153.47AS270068 DESARROLLO DE INFRAESTRUCTURA DE TELECOMPEBitTorrent2052026-10-10 23:07
181.66.151.13AS6147 INTEGRATEL PERU S.A.A.PEBitTorrent1942026-10-10 23:39
190.237.0.152AS6147 INTEGRATEL PERU S.A.A.PEBitTorrent1802026-10-10 02:41
190.235.116.179AS6147 INTEGRATEL PERU S.A.A.PEBitTorrent1702026-10-09 20:04
190.237.1.204AS6147 INTEGRATEL PERU S.A.A.PEBitTorrent1292026-10-06 21:33
38.25.17.204AS265691 WI-NET TELECOM S.A.C.PEBitTorrent1192026-10-11 01:14
179.6.23.236AS12252 America Movil Peru S.A.C.PEBitTorrent1172026-10-11 00:25
200.48.38.104AS6147 INTEGRATEL PERU S.A.A.PEBitTorrent1002026-10-10 21:18

Latest datagrams