IP report
37.49.227.136
payload staging hostThis IP has not connected to our sensors directly. It appears as a malware staging host inside captured payloads.
Referenced in captured payloads
Our honeypots were instructed to download malware from this host. It has not connected to our sensors itself; it appears as the download target inside 1 captured dropper payload.
| File | SHA-256 | VT | Via | First seen |
|---|---|---|---|---|
| l.sh | a1ec3e5dc2ae1381… | 10/75 | busybox-wget | 2026-08-02 |
| [http]://37[.]49[.]227[.]136/l.sh | ||||