Internet-wide scanning behaviour, command-and-control indicator matches, Tor exit status and the services Shodan has observed on one IPv4 address.
Listed as a known command-and-control indicator (Quasar RAT). This is not background noise — treat traffic to or from it as an incident lead.
20.52.184.247cloudself-signedOpen ports, software fingerprints and matched CVEs come from Shodan InternetDB, refreshed daily. Shodan did the scanning; we only read its index. A CVE listed here means a service banner matched a version known to be affected — not that exploitation was confirmed, and not that a backported fix is absent.
Scanning behaviour from the GreyNoise Community API. Indicators from abuse.ch Feodo, C2IntelFeeds, URLhaus and ThreatFox, mirrored nightly. Tor exit list from the Tor Project, refreshed every six hours. Open services from Shodan InternetDB, refreshed daily. We never connect to the address itself.