Rosetta Intel
Datasets/KEV CatalogThreat ActorsC2 InfrastructureAttack Surface
Rosetta Lab ↗contact@rosettalab.devclick to copy
© 2026 BlurHorizon, LLC
← Attack surface
Datasets

IP triage

GreyNoise · IOCs · Tor · Shodan

Internet-wide scanning behaviour, command-and-control indicator matches, Tor exit status and the services Shodan has observed on one IPv4 address.

Clear
Verdict

59.97.253.202

Worth chasing

Listed as a known command-and-control indicator (malware_download). This is not background noise — treat traffic to or from it as an incident lead.

GreyNoise
unknown
last seen 2026-09-26
Known C2
1
urlhaus
Tor exit
No
not in the current exit list
Indicator records
2026-09-26
malware_download
urlhaus · first seen 2026-09-26
Exposed services

Shodan has no record for this host. Its scanners saw nothing listening, or have not visited recently — that is not the same as nothing being exposed.

GreyNoise ↗

Scanning behaviour from the GreyNoise Community API. Indicators from abuse.ch Feodo, C2IntelFeeds, URLhaus and ThreatFox, mirrored nightly. Tor exit list from the Tor Project, refreshed every six hours. Open services from Shodan InternetDB, refreshed daily. We never connect to the address itself.