Substantial Risk
IP 66.132.172.173 is a high-risk address associated with extensive hacking activity and web application probing, with a threat level rating of 8 out of 10 and a confidence score of 89 percent based on 5,642 reported incidents detected by automated honeypot sensors. The IP, registered to Censys, Inc. under ASN AS398324 in the United States, has demonstrated persistent malicious behavior across a six-month period from March 2026 through August 2026, with an activity frequency rated 8 out of 10.
The overwhelming majority of reports classify the observed activity as general hacking attempts, accounting for 20 of the 21 categorized incidents, with one additional web application attack report. Detection data from automated honeypot sensors revealed a Suricata alert indicating an application layer protocol mismatch between web application traffic and probing behavior in both directions, suggesting the IP is actively engaging services while simultaneously attempting to fingerprint or exploit web-facing applications. The sheer volume of reports—more than 5,600 over approximately six months—indicates sustained, automated scanning or exploitation efforts rather than opportunistic or isolated probe attempts.
The dominant threat category, general hacking activity, encompasses unauthorized access attempts, intrusion probing, and exploitation of vulnerable services exposed to the internet. When combined with the secondary web application attack classification, this profile suggests the IP is part of automated scanning infrastructure designed to identify and exploit weaknesses in web servers, applications, and network services. A protocol mismatch detected by Suricata often indicates reconnaissance activity where attackers test multiple response protocols to map service configurations or exploit poorly configured applications that exhibit inconsistent behavior.
Site operators with publicly accessible services should consider blocking or rate-limiting traffic from this IP address, particularly for SSH, Telnet, HTTP/HTTPS, and other remote access interfaces. Implementing fail2ban or similar intrusion prevention tools can automatically block repeated connection attempts originating from high-volume scanning sources. Web application firewalls should be reviewed and configured to detect and mitigate probing patterns associated with web app reconnaissance. Regular security audits, prompt patching of internet-facing services, and monitoring of authentication logs for unusual source IPs will further reduce exposure to the threat patterns this address represents.