Rosetta Intel
Datasets/KEV CatalogThreat ActorsC2 InfrastructureAttack Surface
Rosetta Lab ↗contact@rosettalab.devclick to copy
© 2026 BlurHorizon, LLC
Datasets

C2 Infrastructure

Hosting profile

Where known command-and-control hosts live — by network, country, open port and software.

9,687 hosts·4,867 with a Shodan record·1134 ASNs·118 countries·Updated 2026-09-26

Profiling runs nightly and is incremental: coverage grows until every indicator address has been looked up, then each host is refreshed every thirty days. 9,687 / 9,971

Hosting

Hosting networks

Autonomous systems ranked by how many indicator addresses they announce. Country is the prefix’s registry country, taken as the most common one when a network spans several. The right-hand figure is how many of its hosts Shodan has a record for.

2,702
CHINA169-Backbone - CHINA UNICOM China169 Backbone
AS4837 · CN · malware_download · Unknown malware · Mirai
566 / 2702
401
GOOGLE-CLOUD-PLATFORM - Google LLC
AS396982 · US · Unknown malware · Sliver · Evilginx
334 / 401
311
CHINANET-BACKBONE - No.31,Jin-rong Street
AS4134 · CN · malware_download · Unknown malware · AdaptixC2
58 / 311
245
AROSS-AS - AROSSCLOUD INC.
AS400619 · SC · VShell · PureRAT · Possible Cobaltstrike C2 IP
236 / 245
225
DIGITALOCEAN-ASN - DigitalOcean, LLC
AS14061 · US · Aisuru · Unknown malware · Jackskid
148 / 225
207
TENCENT-NET-AP - Shenzhen Tencent Computer Systems Company Limited
AS45090 · CN · Possible Cobaltstrike C2 IP · VShell · Cobalt Strike
180 / 207
172
ALIBABA-CN-NET - Hangzhou Alibaba Advertising Co.,Ltd.
AS37963 · CN · Possible Cobaltstrike C2 IP · VShell · Cobalt Strike
117 / 172
158
CENSYS-ARIN-01 - Censys, Inc.
AS398324 · US · Unknown malware
5 / 158
125
ALIBABA-CN-NET - Alibaba (US) Technology Co., Ltd.
AS45102 · US · Unknown malware · Possible Cobaltstrike C2 IP · malware_download
99 / 125
117
GLOBE-MOBILE-5TH-GEN-AS - Globe Telecom Inc.
AS132199 · PH · malware_download
111 / 117
112
Telkom SA Ltd. - Telkom SA Ltd.
AS37457 · ZA · malware_download
32 / 112
96
CHINA169-GZ - China Unicom IP network China169 Guangdong province
AS17816 · CN · malware_download
3 / 96
86
MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation
AS8075 · US · Unknown malware · Sliver · AdaptixC2
32 / 86
84
telkomnet-as-ap - PT Telekomunikasi Indonesia
AS7713 · ID · malware_download · Unknown malware · XMRIG
23 / 84
83
AMAZON-02 - Amazon.com, Inc.
AS16509 · US · Unknown malware · ValleyRAT · AsyncRAT
45 / 83
81
STORMCLOUD-AS - Storm Industries LLC
AS219502 · UA · malware_download · Unknown malware · Mirai
59 / 81
79
AS-COLOCROSSING - HostPapa
AS36352 · US · malware_download · Remcos · Unknown malware
67 / 79
77
HETZNER-AS - Hetzner Online GmbH
AS24940 · DE · Vidar · Unknown malware · malware_download
63 / 77
76
BSNL-NIB - National Internet Backbone
AS9829 · IN · malware_download · Unknown malware
9 / 76
63
Al Madar Al Jadeed Joint Stock Company - Al Madar Al Jadeed Joint Stock Company
AS328200 · LY · Unknown malware
0 / 63
60
OVH - OVH SAS
AS16276 · FR · Unknown malware · malware_download · Remus
52 / 60
58
CTGSERVERLIMITED-AS-AP - CTG Server Limited
AS152194 · SG · malware_download · ValleyRAT · PureRAT
44 / 58
58
HURRICANE - Hurricane Electric LLC
AS6939 · US · Unknown malware
58 / 58
57
AS-VULTR - The Constant Company, LLC
AS20473 · US · Unknown malware · Jackskid · Possible Cobaltstrike C2 IP
44 / 57
55
CYBERNET-AP - Cyber Internet Services (Pvt) Ltd.
AS9541 · PK · malware_download · Unknown malware
27 / 55
Hosts by country
TEAM CYMRU · PREFIX COUNTRY
9,687 hosts
CN3,653US2,129SC383DE326IN212SG202RU192PK151HK
Open ports on hosts with a record
SHODAN INTERNETDB
4,867 with a Shodan record
801,702 · http221,584 · ssh4431,018 · https3389481 · rdp21395 · ftp53366 · dns123355445
Software fingerprints
CPE · APPLICATIONS
openssh1,590 · openbsdnginx863 · f5ntp328 · ntphttp server316 · apachepython131 · pythoncobalt strike103 · helpsystemsphp85 · phpjquery
By indicator label
OUR IOC MIRROR · DISTINCT ADDRESSES
malware_download4,837 · 4623 profiledUnknown malware2,429 · 2419 profiledVShell485 · 482 profiledPossible Cobaltstrike C2 IP386 · 385 profiledCobalt Strike277 · 271 profiledPureRAT254 · 250 profiledRemcos191 · 184 profiled

Addresses are the IP indicators mirrored nightly from abuse.ch Feodo, C2IntelFeeds, URLhaus and ThreatFox. Network, prefix and country come from Team Cymru’s IP-to-ASN service; open ports, software fingerprints and matched CVEs from Shodan InternetDB. Shodan did the scanning; we only read its index. A host Shodan has no record for still counts in the network figures, but not in ports or software.

138
AE136
BR132
PH131
290 · smb
135275 · msrpc
5985272
8080235 · http alt
23202 · telnet
8443148 · https alt
5060122
74 · jquery
lighttpd71 · lighttpd
mysql66 · oracle
openssl64 · openssl
bootstrap54 · getbootstrap
postfix52 · postfix
internet information services49 · microsoft
Operating systems
CPE · OPERATING SYSTEMS
ubuntu linux1,218 · canonicallinux kernel495 · linuxdebian linux255 · debianwindows79 · microsoftcentos18 · centos
AsyncRAT126 · 122 profiled
Sliver121 · 121 profiled
Aisuru112 · 105 profiled
AdaptixC2105 · 101 profiled
Jackskid91 · 91 profiled

Labels are kept as each feed publishes them — Feodo names the botnet, C2IntelFeeds writes a description — and are not merged.