Datasets
C2 Infrastructure Hosting profile
Where known command-and-control hosts live — by network, country, open port and software.
9,687 hosts· 4,867 with a Shodan record· 1134 ASNs· 118 countries· Updated 2026-09-26
Profiling runs nightly and is incremental: coverage grows until every indicator address has been looked up, then each host is refreshed every thirty days. 9,687 / 9,971
Hosting
Hosting networks Autonomous systems ranked by how many indicator addresses they announce. Country is the prefix’s registry country, taken as the most common one when a network spans several. The right-hand figure is how many of its hosts Shodan has a record for.
2,702
CHINA169-Backbone - CHINA UNICOM China169 Backbone
AS4837 · CN · malware_download · Unknown malware · Mirai
566 / 2702
401
GOOGLE-CLOUD-PLATFORM - Google LLC
AS396982 · US · Unknown malware · Sliver · Evilginx
334 / 401
311
CHINANET-BACKBONE - No.31,Jin-rong Street
AS4134 · CN · malware_download · Unknown malware · AdaptixC2
58 / 311
245
AROSS-AS - AROSSCLOUD INC.
AS400619 · SC · VShell · PureRAT · Possible Cobaltstrike C2 IP
236 / 245
225
DIGITALOCEAN-ASN - DigitalOcean, LLC
AS14061 · US · Aisuru · Unknown malware · Jackskid
148 / 225
207
TENCENT-NET-AP - Shenzhen Tencent Computer Systems Company Limited
AS45090 · CN · Possible Cobaltstrike C2 IP · VShell · Cobalt Strike
180 / 207
172
ALIBABA-CN-NET - Hangzhou Alibaba Advertising Co.,Ltd.
AS37963 · CN · Possible Cobaltstrike C2 IP · VShell · Cobalt Strike
117 / 172
158
CENSYS-ARIN-01 - Censys, Inc.
AS398324 · US · Unknown malware
5 / 158
125
ALIBABA-CN-NET - Alibaba (US) Technology Co., Ltd.
AS45102 · US · Unknown malware · Possible Cobaltstrike C2 IP · malware_download
99 / 125
117
GLOBE-MOBILE-5TH-GEN-AS - Globe Telecom Inc.
AS132199 · PH · malware_download
111 / 117
112
Telkom SA Ltd. - Telkom SA Ltd.
AS37457 · ZA · malware_download
32 / 112
96
CHINA169-GZ - China Unicom IP network China169 Guangdong province
AS17816 · CN · malware_download
3 / 96
86
MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation
AS8075 · US · Unknown malware · Sliver · AdaptixC2
32 / 86
84
telkomnet-as-ap - PT Telekomunikasi Indonesia
AS7713 · ID · malware_download · Unknown malware · XMRIG
23 / 84
83
AMAZON-02 - Amazon.com, Inc.
AS16509 · US · Unknown malware · ValleyRAT · AsyncRAT
45 / 83
81
STORMCLOUD-AS - Storm Industries LLC
AS219502 · UA · malware_download · Unknown malware · Mirai
59 / 81
79
AS-COLOCROSSING - HostPapa
AS36352 · US · malware_download · Remcos · Unknown malware
67 / 79
77
HETZNER-AS - Hetzner Online GmbH
AS24940 · DE · Vidar · Unknown malware · malware_download
63 / 77
76
BSNL-NIB - National Internet Backbone
AS9829 · IN · malware_download · Unknown malware
9 / 76
63
Al Madar Al Jadeed Joint Stock Company - Al Madar Al Jadeed Joint Stock Company
AS328200 · LY · Unknown malware
0 / 63
60
OVH - OVH SAS
AS16276 · FR · Unknown malware · malware_download · Remus
52 / 60
58
CTGSERVERLIMITED-AS-AP - CTG Server Limited
AS152194 · SG · malware_download · ValleyRAT · PureRAT
44 / 58
58
HURRICANE - Hurricane Electric LLC
AS6939 · US · Unknown malware
58 / 58
57
AS-VULTR - The Constant Company, LLC
AS20473 · US · Unknown malware · Jackskid · Possible Cobaltstrike C2 IP
44 / 57
55
CYBERNET-AP - Cyber Internet Services (Pvt) Ltd.
AS9541 · PK · malware_download · Unknown malware
27 / 55
Hosts by country
TEAM CYMRU · PREFIX COUNTRY
9,687 hosts
CN 3,653 US 2,129 SC 383 DE 326 IN 212 SG 202 RU 192 PK 151 HK
Open ports on hosts with a record
SHODAN INTERNETDB
4,867 with a Shodan record
80 1,702 · http 22 1,584 · ssh 443 1,018 · https 3389 481 · rdp 21 395 · ftp 53 366 · dns 123 355 445
Software fingerprints
CPE · APPLICATIONS
openssh 1,590 · openbsd nginx 863 · f5 ntp 328 · ntp http server 316 · apache python 131 · python cobalt strike 103 · helpsystems php 85 · php jquery
By indicator label
OUR IOC MIRROR · DISTINCT ADDRESSES
malware_download 4,837 · 4623 profiled Unknown malware 2,429 · 2419 profiled VShell 485 · 482 profiled Possible Cobaltstrike C2 IP 386 · 385 profiled Cobalt Strike 277 · 271 profiled PureRAT 254 · 250 profiled Remcos 191 · 184 profiled
Addresses are the IP indicators mirrored nightly from abuse.ch Feodo, C2IntelFeeds, URLhaus and ThreatFox. Network, prefix and country come from Team Cymru’s IP-to-ASN service; open ports, software fingerprints and matched CVEs from Shodan InternetDB. Shodan did the scanning; we only read its index. A host Shodan has no record for still counts in the network figures, but not in ports or software.