General Information

Submitter Diversity: Low
Risk (0-10)details: 1
IP Address (click for more detail): 194.50.16.198
Hostname: 194.50.16.198
Country:  US
ASN: 49870
AS Name:  AS49870-BV - Alsycon B.V., NL
Network:  194.50.16.0/24 (194.50.16.0-194.50.16.255) 194.50.17.0
Reports:  - none -
Targets:  - none -
First Reported: N/A
Most Recent Report: N/A
Comment: - none -
Abuse Contact for AS49870: abuse@westcall.ru
Links to articles about the IP from rosti.bin.re
https://blog.xlab.qianxin.com/gayfemboy-en/ (Mirai)
https://blog.xlab.qianxin.com/gayfemboy/ (Mirai)
https://hivepro.com/threat-advisory/gayfemboy-botnet-evolution-of-a-potent-threat/?utm_sr=(direct)&utm_cmd=(none)&utm_ccn=(not set) (Mirai)

Note: We update the data once an hour. To refresh the data, click here. Not all source IPs in our database are "attackers". There are a few common false positives. For example, hosts that participate in P2P networks, mail servers, load balancers and DNS servers are some of the most common issues. For details, click on the number of reports. Clicking on the number of reports may allow you to conclude if a report is a false positive or not. Scroll down for information from other data feeds.

SSH/Telnet Logs

no ssh logs.

Web Honeypot Logs

Date Reports Different URLs Different User Agents
2026-10-0154122
2026-09-3043112
2026-09-2955122
2026-09-2837191
2026-09-2771311
2026-09-2678121
2026-09-2572131
2026-09-2466131
2026-09-2343101
2026-09-2273131
2026-09-2162281
2026-09-20106281
2026-09-19127271
2026-09-17991

For more details about the web honeypot, see the Weblogs Page. Do not use these reports to identify IP addresses as "bad" for now.

External Threat Feeds

This data was retrieved from various external data feeds.

First Seen Last Seen Feed
2024-11-072026-10-01CI Army List
2025-01-072026-10-01Rosti
Check Threatstop for more data link arrow