UDP traffic
Datagrams matching country:PE sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
8.3K
Datagrams
92
Source addresses
17
Networks
1
Countries
14
Destination ports
Traffic by type
Service queries
2 datagrams from 1 sourceRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest DNS datagram, to 53/udp
payload bytes
00000000 57 f1 e0 3d ba 55 3b ee ad f8 ab f3 ff b4 b8 f0 |W..=.U;.........| 00000010 f6 89 e8 ca 94 83 4a fe 60 62 88 52 82 3b a2 67 |......J.`b.R.;.g| 00000020 b9 a9 8b e9 3f c1 77 43 53 30 fd 52 a5 6f f5 24 |....?.wCS0.R.o.$| 00000030 e3 cc 87 90 f5 99 04 6d ae 43 c0 d6 94 96 c7 59 |.......m.C.....Y| 00000040 9b a9 89 f7 ae 4d 0b be f2 b4 02 6a 10 fc 14 0f |.....M.....j....| 00000050 18 49 6b b5 26 04 e9 51 cd 8f 33 2e 67 02 6f 86 |.Ik.&..Q..3.g.o.| 00000060 3b b8 a3 69 1d 49 72 70 39 ed 8d c2 35 b3 0f 3c |;..i.Irp9...5..<| 00000070 ef b6 19 48 50 24 c1 aa 14 f0 88 07 cb 7d 5f 46 |...HP$.......}_F| 00000080 21 15 74 c3 bb 4a 34 60 f9 1e 7c 20 18 8e 70 9d |!.t..J4`..| ..p.| 00000090 8a 5d ce fe 7a b1 6d 3c d8 eb 26 fc 0a ba 3f e5 |.]..z.m<..&...?.| 000000a0 2a 89 91 69 03 03 26 38 f4 57 95 f3 66 4c 62 eb |*..i..&8.W..fLb.| 000000b0 f9 50 5f 0e 2a 74 69 06 e4 a9 1a 5f 1d df e2 a6 |.P_.*ti...._....| 000000c0 a0 8b ce 52 f7 6d 4b 1f 73 b2 94 95 eb 8d 3e 25 |...R.mK.s.....>%| 000000d0 67 91 8b 03 34 60 eb 47 90 45 dc 77 55 cf 5c a6 |g...4`.G.E.wU.\.| 000000e0 50 72 03 f9 84 47 f5 e5 6f 6e 90 70 4f 21 f6 30 |Pr...G..on.pO!.0| 000000f0 f3 44 85 d2 40 f0 03 9d 99 16 13 6e 4d be 6e ef |.D..@......nM.n.|
Other services
6 datagrams from 3 sourcesFirst packets of sessions with VPN, voice, tunnelling, database and management services.
Latest SOCKS5 datagram, to 16880/udp
payload bytes
00000000 05 00 ff ff 00 fe fe fe fe fd fd fd fd 12 34 56 |..............4V| 00000010 78 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |x...............| 00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000050 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000080 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000090 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 000000f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
Unrecognised
6 datagrams from 6 sourcesDatagrams no decoder recognised. Their first bytes are kept.
Latest Unrecognised datagram, to 11183/udp
payload bytes
00000000 01 1e 71 b3 fb d4 a5 23 24 00 ff ff 00 fe fe fe |..q....#$.......| 00000010 fe fd fd fd fd 12 34 56 78 14 33 2c 5c da eb 5a |......4Vx.3,\..Z| 00000020 62 |b|
Peer-to-peer
8,283 datagrams from 82 sourcesFile-sharing clients trying to reach a peer that used one of these addresses before. This is not scanning, so it is left out of every other figure on this page.
Amplification checks
Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.
| Service | Port | Datagrams | Sources | Factor |
|---|---|---|---|---|
| DNS | 53/udp | 2 | 1 | 28 to 54 |
The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.
Destination ports
Networks
- AS12252 America Movil Peru S.A.C. from 25 sources3,248
- AS265691 WI-NET TELECOM S.A.C. from 20 sources1,834
- AS6147 INTEGRATEL PERU S.A.A. from 20 sources1,769
- AS269981 COMPUNETWORK S.A.C. from 1 source414
- AS270068 DESARROLLO DE INFRAESTRUCTURA DE TELECOM from 7 sources368
- AS272836 CALA SERVICIOS INTEGRALES E.I.R.L. from 3 sources352
- AS272106 CORPORACION TARAZONA CATV S.A.C. from 3 sources57
- AS262210 VIETTEL PERU S.A.C. from 2 sources50
- AS273133 CONEX TV E.I.R.L. from 1 source47
- AS267749 INVERSIONES TELCOTEL SAC from 1 source36
Countries
- PE Peru8,297
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 179.6.16.189 | AS12252 America Movil Peru S.A.C. | PE | BitTorrent | 964 | 2026-10-11 03:15 |
| 179.6.0.117 | AS12252 America Movil Peru S.A.C. | PE | BitTorrent | 769 | 2026-10-11 04:55 |
| 38.25.25.58 | AS265691 WI-NET TELECOM S.A.C. | PE | BitTorrent | 675 | 2026-10-08 03:48 |
| 190.43.149.108 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 507 | 2026-10-10 02:49 |
| 38.25.8.41 | AS265691 WI-NET TELECOM S.A.C. | PE | BitTorrent | 469 | 2026-10-11 04:42 |
| 179.6.3.87 | AS12252 America Movil Peru S.A.C. | PE | BitTorrent | 419 | 2026-10-10 21:09 |
| 200.215.249.48 | AS269981 COMPUNETWORK S.A.C. | PE | BitTorrent | 414 | 2026-10-10 21:11 |
| 38.255.109.186 | AS272836 CALA SERVICIOS INTEGRALES E.I.R.L. | PE | BitTorrent | 346 | 2026-10-10 21:48 |
| 179.6.3.78 | AS12252 America Movil Peru S.A.C. | PE | BitTorrent | 321 | 2026-10-09 20:47 |
| 179.6.15.158 | AS12252 America Movil Peru S.A.C. | PE | BitTorrent | 287 | 2026-10-10 07:21 |
| 201.230.200.72 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 261 | 2026-10-11 05:00 |
| 38.25.83.145 | AS265691 WI-NET TELECOM S.A.C. | PE | BitTorrent | 230 | 2026-10-11 05:40 |
| 38.250.153.47 | AS270068 DESARROLLO DE INFRAESTRUCTURA DE TELECOM | PE | BitTorrent | 205 | 2026-10-10 23:07 |
| 181.66.151.13 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 194 | 2026-10-10 23:39 |
| 190.237.0.152 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 180 | 2026-10-10 02:41 |
| 190.235.116.179 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 170 | 2026-10-09 20:04 |
| 190.237.1.204 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 129 | 2026-10-06 21:33 |
| 38.25.17.204 | AS265691 WI-NET TELECOM S.A.C. | PE | BitTorrent | 120 | 2026-10-11 07:20 |
| 179.6.23.236 | AS12252 America Movil Peru S.A.C. | PE | BitTorrent | 117 | 2026-10-11 00:25 |
| 200.48.38.104 | AS6147 INTEGRATEL PERU S.A.A. | PE | BitTorrent | 100 | 2026-10-10 21:18 |
Latest datagrams
payload bytes
00000000 41 00 60 90 0a 4f e9 e6 00 00 00 00 00 00 00 00 |A.`..O..........| 00000010 50 51 00 00 |PQ..|
payload bytes
00000000 41 00 20 ed 9d 8c db b7 00 00 00 00 00 10 00 00 |A. .............| 00000010 7a fb 00 00 |z...|
payload bytes
00000000 41 00 94 d7 f4 41 75 a5 00 00 00 00 00 10 00 00 |A....Au.........| 00000010 45 1d 00 00 |E...|
payload bytes
00000000 41 00 94 d7 f3 e5 31 96 00 00 00 00 00 10 00 00 |A.....1.........| 00000010 45 1d 00 00 |E...|
payload bytes
00000000 41 00 94 d7 f3 b0 ff 02 00 00 00 00 00 10 00 00 |A...............| 00000010 45 1d 00 00 |E...|
payload bytes
00000000 41 00 b5 53 b3 51 08 70 00 00 00 00 00 10 00 00 |A..S.Q.p........| 00000010 1c 32 00 00 |.2..|
payload bytes
00000000 41 00 b5 53 b2 f3 a5 0a 00 00 00 00 00 10 00 00 |A..S............| 00000010 1c 32 00 00 |.2..|
payload bytes
00000000 41 00 b5 53 b2 c2 66 b5 00 00 00 00 00 10 00 00 |A..S..f.........| 00000010 1c 32 00 00 |.2..|
payload bytes
00000000 41 00 2c 03 46 8c 12 4b 00 00 00 00 00 10 00 00 |A.,.F..K........| 00000010 11 6e 00 00 |.n..|
payload bytes
00000000 41 00 ec 69 dc b5 4f 02 00 00 00 00 00 10 00 00 |A..i..O.........| 00000010 ee 55 00 00 |.U..|
payload bytes
00000000 41 00 2c 03 46 30 14 d1 00 00 00 00 00 10 00 00 |A.,.F0..........| 00000010 11 6e 00 00 |.n..|
payload bytes
00000000 41 00 ec 69 dc 58 99 b8 00 00 00 00 00 10 00 00 |A..i.X..........| 00000010 ee 55 00 00 |.U..|
payload bytes
00000000 41 00 2c 03 45 fb fb 19 00 00 00 00 00 10 00 00 |A.,.E...........| 00000010 11 6e 00 00 |.n..|
payload bytes
00000000 41 00 ec 69 dc 25 92 52 00 00 00 00 00 10 00 00 |A..i.%.R........| 00000010 ee 55 00 00 |.U..|
payload bytes
00000000 41 00 c9 ec a2 cc 64 ca 00 00 00 00 00 10 00 00 |A.....d.........| 00000010 49 cc 00 00 |I...|