IP Address

172.86.66.146

IPv4 Public
DE DE
AS14956
ROUTERHOSTING
330 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
74% Confidence
330 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
DE
DE Location
ROUTERHOSTING ASN 14956
330 Reports
Honeypot Data Source

Severe Risk

IP address 172.86.66.146 is a critical-risk address operating from German network infrastructure under AS14956 (ROUTERHOSTING), with 330 accumulated abuse reports and a maximum threat score of 10/10 indicating severe malicious activity. All recent detections consistently flag unauthorized hacking attempts, placing this IP squarely in the highest-risk category for any exposed service. The concentration of reports against automated honeypot sensors demonstrates sustained, deliberate targeting of internet-facing systems rather than incidental scanning.

Analysis of the available data reveals a substantial volume of hostile activity originating from this German-hosted address during November 2025. The 330 total reports correlate with confirmed detection across 20 separate honeypot sensors, suggesting the threat actor operates infrastructure capable of widespread scanning or distributes attack payloads across multiple sources. Despite a low activity-frequency metric of 0/10 in recent intervals, the historical report count signals persistent engagement with vulnerable targets over time. The AS14956 autonomous system assignment through ROUTERHOSTING indicates the source resides within a hosting or infrastructure provider environment, a common characteristic for IP addresses involved in automated exploitation campaigns.

The dominant threat classification of hacking encompasses systematic intrusion attempts, vulnerability probing, and unauthorized access campaigns against internet-connected services. This pattern poses concrete risk to any exposed SSH, Telnet, HTTP interfaces, or other network services operated by this IP's targeting scope. Attackers leveraging such infrastructure typically conduct credential stuffing, exploit enumeration, and payload delivery attempts at scale, exploiting unpatched software or misconfigured services to establish persistent footholds. The high confidence score of 74% grounds these assessments in substantial sensor and community reporting data rather than isolated alerts.

Network defenders should treat IP address 172.86.66.146 as definitively hostile and implement immediate blocking at perimeter firewalls or edge routers. Deploying fail2ban, similar log-analysis tools, or web-application firewalls can automatically detect and throttle repeated intrusion patterns from this source. Enforcing strong authentication on all externally accessible services, disabling unused protocols, and maintaining rigorous patch management substantially reduces the attack surface these hacking attempts seek to exploit. Continuous monitoring of authentication logs for sourcing from this address will reveal any successful breach attempts requiring incident response. Organizations operating publicly accessible services should consider reputation-based blocking feeds and threat-intelligence correlation to proactively deny traffic from known high-risk addresses like this one.

More threatening than 97% of monitored IPs

Threat Categories

Hacking 30

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 14956) with generally good reputation. The ISP ROUTERHOSTING maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 59% High Confidence

Confidence History

24. Nov 2025
74% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Technical Details

Basic Information

IP Address
172.86.66.146
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class B

Geolocation

Country
DE DE
ASN
AS14956
ISP
ROUTERHOSTING

DNS Information

Reverse DNS
146.66.86.172.static.cloudzy.com
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
330
First Reported
20 Nov 2025
Last Reported
24 Nov 2025, 05:03

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS14956
RouterHosting LLC
US US

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

170
Total IPs Monitored
21,290
Total Reports
125.2
Reports per IP

Network Context

This IP address belongs to RouterHosting LLC (AS14956), which manages 170 IP addresses in our monitoring system. Out of these, 21,290 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

97 %

Global Threat Ranking

This IP is more threatening than 97% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 767,879 reported IPs worldwide

Threat Level 10/10 avg: 5.8 ++
Total Reports 330 avg: 9 ++

Network Comparison

Compared against 536 IPs in ASN 14956

Threat Level 10/10 network avg: 6.8 +
Total Reports 330 network avg: 50 ++
Network ROUTERHOSTING has overall threat level 3/10

Geographic Comparison

Compared against 15,831 IPs in DE

Threat Level 10/10 country avg: 6.7 +
Total Reports 330 country avg: 34 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

698,535 threat incidents tracked globally • Last 24h: 23,253 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    134,984 19.3%
  2. 02
    BR
    Brazil BR
    109,432 15.7%
  3. 03
    IN
    India IN
    75,807 10.9%
  4. 04
    CN
    China CN
    43,137 6.2%
  5. 05
    SC
    SC SC
    29,184 4.2%
  6. 06
    NL
    Netherlands NL
    16,476 2.4%
  7. 07
    AR
    Argentina AR
    16,068 2.3%
  8. 08
    DE
    Germany DE THIS IP
    15,831 2.3%
  9. 09
    PK
    Pakistan PK
    15,218 2.2%
  10. 10
    CO
    Colombia CO
    15,077 2.2%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.8/10 Avg Threat
95% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "172.86.66.146",
    "threat_level": 10,
    "confidence_score": 74,
    "total_reports": 330,
    "country_code": "DE",
    "isp_name": "ROUTERHOSTING",
    "asn": "14956",
    "first_reported": "2025-11-20 21:10:20",
    "last_reported": "2025-11-24 05:03:13",
    "exported_at": "2026-09-20T23:20:18+02:00",
    "source": "https://reportedip.com/ip/172.86.66.146/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.