IP report
198.144.179.82
payload staging hostThis IP has not connected to our sensors directly. It appears as a malware staging host inside captured payloads.
Referenced in captured payloads
Our honeypots were instructed to download malware from this host. It has not connected to our sensors itself; it appears as the download target inside 2 captured dropper payloads.
| File | SHA-256 | VT | Via | First seen |
|---|---|---|---|---|
| 1.sh | 1d64be0ba1bd9924… | 7/75 | busybox-wget | 2026-08-28 |
| [http]://198[.]144[.]179[.]82:80/1.sh | ||||
| 1[1].sh | ac619a5cba97b835… | 6/75 | wget | 2026-08-18 |
| [http]://198[.]144[.]179[.]82:80/1.sh | ||||