HoneyLabs

UDP traffic

Datagrams matching port:5683 sent to HoneyLabs sensors over UDP in the last 24 hours. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

27

Datagrams

13

Source addresses

9

Networks

6

Countries

1

Destination ports

Traffic by type

Service queries

27 datagrams from 13 sources

Requests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.

Latest CoAP datagram, to 5683/udp

@·}p·.well-known·core

payload bytes
00000000  40 01 7d 70 bb 2e 77 65  6c 6c 2d 6b 6e 6f 77 6e  |@.}p..well-known|
00000010  04 63 6f 72 65                                    |.core|

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
45.198.224.251AS215925 Vpsvault.host LtdUSCoAP62026-10-10 14:13
45.205.1.231AS215925 Vpsvault.host LtdBRCoAP42026-10-10 17:32
151.243.11.230AS209630 LLC Vash Kredit BankAECoAP42026-10-10 11:52
185.73.23.133AS29484 Ruhr-Universitaet BochumDECoAP32026-10-11 05:05
146.88.241.150AS20052 Arbor Networks, Inc.USCoAP22026-10-11 04:02
165.154.43.179AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITHKCoAP12026-10-11 04:59
147.185.132.249AS396982 Google LLCUSCoAP12026-10-10 11:59
66.132.224.27AS398324 Censys, Inc.USCoAP12026-10-10 13:06
65.49.1.103AS6939 Hurricane Electric LLCUSCoAP12026-10-10 05:44
198.235.24.241AS396982 Google LLCUSCoAP12026-10-10 16:50
65.49.20.70AS6939 Hurricane Electric LLCUSCoAP12026-10-11 03:30
93.123.109.214AS48090 Techoff Srv LimitedBGCoAP12026-10-10 18:23
146.88.241.40AS20052 Arbor Networks, Inc.USCoAP12026-10-11 03:14

Latest datagrams