HoneyLabs

IP report

166.0.192.57

payload staging host

This IP has not connected to our sensors directly. It appears as a malware staging host inside captured payloads.

Referenced in captured payloads

Our honeypots were instructed to download malware from this host. It has not connected to our sensors itself; it appears as the download target inside 2 captured dropper payloads.

FileSHA-256VTViaFirst seen
loader930e5c1df1a8fd44…6/75curl2026-08-14
[http]://166[.]0[.]192[.]57/loader
cumshotnews2690b9cf6cf4fb68…12/74curl2026-08-06
[http]://166[.]0[.]192[.]57/cumshotnews
See all captured payloads →

Try another

Look up a different IP

Or pick from the top 10 attackers live right now.

Build with the data

Get an API key

MCP for Claude / Cursor or raw HTTP JSON-RPC.