Rosetta Intel
Datasets/KEV CatalogThreat ActorsC2 InfrastructureAttack Surface
Rosetta Lab ↗contact@rosettalab.devclick to copy
© 2026 BlurHorizon, LLC
← Attack surface
Datasets

IP triage

GreyNoise · IOCs · Tor · Shodan

Internet-wide scanning behaviour, command-and-control indicator matches, Tor exit status and the services Shodan has observed on one IPv4 address.

Clear
Verdict

20.52.184.247

Worth chasing

Listed as a known command-and-control indicator (Quasar RAT). This is not background noise — treat traffic to or from it as an incident lead.

GreyNoise
Not observed
no internet-wide scanning seen
Known C2
1
threatfox
Tor exit
No
not in the current exit list
Indicator records
2026-09-26
Quasar RAT
threatfox · first seen 2026-09-26
Exposed services
Hosts
1
shodan internetdb
Open ports
1
distinct ports across these hosts
Matched CVEs
No
no version matched a known CVE
20.52.184.247cloudself-signed
Open ports
3389
Software
—
Matched CVEs
—

Open ports, software fingerprints and matched CVEs come from Shodan InternetDB, refreshed daily. Shodan did the scanning; we only read its index. A CVE listed here means a service banner matched a version known to be affected — not that exploitation was confirmed, and not that a backported fix is absent.

Scanning behaviour from the GreyNoise Community API. Indicators from abuse.ch Feodo, C2IntelFeeds, URLhaus and ThreatFox, mirrored nightly. Tor exit list from the Tor Project, refreshed every six hours. Open services from Shodan InternetDB, refreshed daily. We never connect to the address itself.