track source of a strange portscan / portmap attack -- 2

Job ID: 35850324

Budget: €30 – €250 EUR

Hi I have an ongoing problem
from few hours.

My server appears to be performing a portscan
toward 'random' ip addresses and udp ports.

The process that is sending those packets is Asterisk
which was already at version 16.29
and I've upgraded it to the last version, 16.30
but the problem persists.

I can't provide ssh access to the server
but I can provide whatever packets captures you prefer.

I'd like to know the source of the problem,
if it's some virus in the office of the client
or some external attack.

Max 100 euros.