Port 5985

HoneyLabs honeypots recorded 1,374 probes against destination port 5985 from 760 distinct source IP addresses in the last 7 days.

First observed 2026-09-23 02:20:06, most recently 2026-09-30 01:28:17 (UTC).

Most active source addresses

Source IPProbesNetworkCountry
93.174.93.1257IP Volume incNL
152.32.146.16618UCLOUD INFORMATION TECHNOLOGY (HK) LIMITEDJP
89.248.171.2418IP Volume incNL
80.82.77.20214IP Volume incNL
124.106.67.11811Philippine Long Distance Telephone CompanyPH
66.132.186.1919Censys, Inc.US
66.132.186.1999Censys, Inc.US
66.132.172.469Censys, Inc.US

Networks it comes from

ASNOrganisationProbesSource IPs
AS8075Microsoft Corporation170124
AS6939Hurricane Electric LLC11292
AS202425IP Volume inc10910
AS45090Shenzhen Tencent Computer Systems Company Limited10690
AS398324Censys, Inc.9712
AS135377UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED9020

Where it comes from

CountryProbes
United States471
China197
The Netherlands112
India89
Hong Kong78
Japan24

Client strings seen on this port

User agentProbes
Microsoft WinRM Client555
Python WinRM client154
Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)101
Python/3.10 aiohttp/3.8.481
Mozilla/5.0 zgrab/0.x17

Port report

Port report

Loading live data…