HoneyLabs

IP report

150.241.65.250

payload staging host

This IP has not connected to our sensors directly. It appears as a malware staging host inside captured payloads.

Referenced in captured payloads

Our honeypots were instructed to download malware from this host. It has not connected to our sensors itself; it appears as the download target inside 2 captured dropper payloads.

FileSHA-256VTViaFirst seen
j8ohm.exe95871105a8ca339c…14/75wget2026-08-24
hxxp[://]150[.]241[.]65[.]250:889/raul[.]mips
979ecedbf94eca29beecfedc5fccfd78d7ba469e23ce36e15fafa29e96cf979ecedbf94eca29…21/68wget2026-08-23
hxxp[://]150[.]241[.]65[.]250:67/dp[.]sh
See all captured payloads →

Try another

Look up a different IP

Or pick from the top 10 attackers live right now.

Build with the data

Get an API key

MCP for Claude / Cursor or raw HTTP JSON-RPC.