UDP traffic
Datagrams matching port:5683 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.
A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.
192
Datagrams
90
Source addresses
18
Networks
14
Countries
1
Destination ports
Traffic by type
Service queries
192 datagrams from 90 sourcesRequests a service answers without a handshake. Scanners send them to find open DNS, NTP, SNMP or SSDP servers, which are also the servers reflection attacks abuse.
Latest CoAP datagram, to 5683/udp
payload bytes
00000000 40 01 7d 70 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.}p..well-known| 00000010 04 63 6f 72 65 |.core|
Destination ports
- 5683/udp CoAP192
Networks
- AS6939 Hurricane Electric LLC from 38 sources41
- AS215925 Vpsvault.host Ltd from 2 sources38
- AS29484 Ruhr-Universitaet Bochum from 1 source22
- AS209630 LLC Vash Kredit Bank from 1 source12
- AS398324 Censys, Inc. from 11 sources11
- AS51115 HLL LLC from 1 source8
- AS213412 ONYPHE SAS from 6 sources8
- AS396982 Google LLC from 8 sources8
- AS45102 Alibaba (US) Technology Co., Ltd. from 4 sources8
- AS20052 Arbor Networks, Inc. from 4 sources7
Countries
Source addresses (unverified)
| Address | Network | Cc | Sends | Datagrams | Last seen (UTC) |
|---|---|---|---|---|---|
| 185.73.23.133 | AS29484 Ruhr-Universitaet Bochum | DE | CoAP | 22 | 2026-10-11 05:05 |
| 45.205.1.231 | AS215925 Vpsvault.host Ltd | BR | CoAP | 20 | 2026-10-10 17:32 |
| 45.198.224.251 | AS215925 Vpsvault.host Ltd | US | CoAP | 18 | 2026-10-10 14:13 |
| 151.243.11.230 | AS209630 LLC Vash Kredit Bank | AE | CoAP | 12 | 2026-10-10 11:52 |
| 185.94.111.1 | AS51115 HLL LLC | RU | CoAP | 8 | 2026-10-09 11:53 |
| 93.123.109.214 | AS48090 Techoff Srv Limited | BG | CoAP | 5 | 2026-10-10 18:23 |
| 146.88.241.150 | AS20052 Arbor Networks, Inc. | US | CoAP | 4 | 2026-10-11 04:02 |
| 172.105.16.212 | AS63949 Akamai Connected Cloud | CA | CoAP | 4 | 2026-10-08 15:15 |
| 193.47.62.187 | AS216014 BestDC Limited | BG | CoAP | 4 | 2026-10-07 13:29 |
| 64.89.163.247 | AS401626 Netiface America, Inc. | US | CoAP | 3 | 2026-10-08 05:18 |
| 64.62.197.187 | AS6939 Hurricane Electric LLC | US | CoAP | 2 | 2026-10-07 08:18 |
| 8.211.0.173 | AS45102 Alibaba (US) Technology Co., Ltd. | DE | CoAP | 2 | 2026-10-08 13:49 |
| 118.26.104.19 | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT | GB | CoAP | 2 | 2026-10-06 21:40 |
| 217.60.76.129 | AS401626 Netiface America, Inc. | AE | CoAP | 2 | 2026-10-09 10:42 |
| 47.84.101.219 | AS45102 Alibaba (US) Technology Co., Ltd. | SG | CoAP | 2 | 2026-10-06 07:46 |
| 64.62.156.54 | AS6939 Hurricane Electric LLC | US | CoAP | 2 | 2026-10-10 00:12 |
| 91.230.168.119 | AS213412 ONYPHE SAS | US | CoAP | 2 | 2026-10-10 02:22 |
| 64.62.156.58 | AS6939 Hurricane Electric LLC | US | CoAP | 2 | 2026-10-09 01:32 |
| 176.65.134.60 | AS51396 Pfcloud UG (haftungsbeschrankt) | DE | CoAP | 2 | 2026-10-09 17:01 |
| 47.77.235.89 | AS45102 Alibaba (US) Technology Co., Ltd. | US | CoAP | 2 | 2026-10-09 09:44 |
Latest datagrams
payload bytes
00000000 40 01 7d 70 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.}p..well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 01 ce bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 7d 70 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.}p..well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 7d 70 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.}p..well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 73 6a |@.sj|
payload bytes
00000000 40 01 7d 70 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.}p..well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 7d 70 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.}p..well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 44 02 b2 26 63 c0 e1 1d b4 65 78 65 63 11 00 3d |D..&c....exec..=| 00000010 15 43 61 6d 65 6c 45 78 65 63 43 6f 6d 6d 61 6e |.CamelExecComman| 00000020 64 45 78 65 63 75 74 61 62 6c 65 3d 2f 62 69 6e |dExecutable=/bin| 00000030 2f 73 68 0d 26 43 61 6d 65 6c 45 78 65 63 43 6f |/sh.&CamelExecCo| 00000040 6d 6d 61 6e 64 41 72 67 73 3d 2d 63 20 27 65 63 |mmandArgs=-c 'ec| 00000050 68 6f 20 43 56 45 32 30 32 36 33 33 34 35 33 61 |ho CVE202633453a| 00000060 6c 62 69 69 73 72 74 27 ff 70 72 6f 62 65 |lbiisrt'.probe|
payload bytes
00000000 40 01 01 01 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 01 01 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 01 01 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 01 01 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 01 ce bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 01 01 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|
payload bytes
00000000 40 01 01 01 bb 2e 77 65 6c 6c 2d 6b 6e 6f 77 6e |@.....well-known| 00000010 04 63 6f 72 65 |.core|