IP Address

66.132.172.175

IPv4 Public
US US
AS398324
Censys, Inc.
5,785 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
89% Confidence
5,785 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
US
US Location
Censys, Inc. ASN 398324
5,785 Reports
Honeypot Data Source

Critical Alert

IP 66.132.172.175 is a critical-risk address associated with prolific hacking activity, having generated 5767 abuse reports from automated honeypot sensors between March and August 2026. With a threat level scored at 10 out of 10 and an activity frequency rated 8 out of 10, this IP represents one of the most consistently reported sources of intrusion attempts in recent observation periods.

The dataset reveals sustained malicious behavior from this address over approximately six months. All 5767 reports originated from automated honeypot sensors, indicating systematic, automated attack infrastructure rather than opportunistic scanning. The IP is registered to AS398324, operated by Censys, Inc., and geolocated to the United States. The high report volume combined with the 89% confidence score suggests reliable detection of hostile intent. Despite the US origin and the association with a known network operator, the threat classification remains squarely within the hacking category, encompassing vulnerability exploitation, intrusion attempts, and unauthorized access vectors.

Hacking activity as classified in these reports encompasses automated exploitation attempts against exposed services, vulnerability scanning, and credential-based intrusion probes. The sheer volume of reports indicates that this IP is engaged in continuous, broad-spectrum scanning of internet-facing systems. For an organization with exposed SSH, RDP, web applications, or other network services, encounters with this address pose a direct risk of compromise through brute-force attempts or exploitation of unpatched vulnerabilities. The persistent nature of the activity suggests an automated bot or organized scanning campaign rather than isolated probes.

Organizations should implement immediate blocking or rate-limiting measures for this IP at the network edge or firewall level. Deploying intrusion detection systems or security tools such as fail2ban can automate the identification and blocking of such patterns. All exposed services should be audited for compliance with security best practices, including strong authentication requirements, principle of least privilege, and regular vulnerability patching. Maintaining detailed logs and monitoring for repeated connection attempts from this address will support both incident response and ongoing threat intelligence gathering.

More threatening than 98% of monitored IPs

Threat Categories

Hacking 30

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Behavioral Analysis

Activity Pattern: Consistent Activity

Steady malicious activity over 4 weeks indicates persistent threat actor operations.

First Observed 8. July 2026
Last Activity 6. August 2026
Recent (7 days) 261 incidents

Reputable Network

This IP is hosted on a network (ASN 398324) with generally good reputation. The ISP Censys, Inc. maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Long-term blocking recommended.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 8/10 High
Confidence Score 89% Verified

Confidence History

5. Aug 2026 - 6. Aug 2026
89% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%

Technical Details

Basic Information

IP Address
66.132.172.175
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
AS398324
ISP
Censys, Inc.

DNS Information

Reverse DNS
175.172.132.66.censys-scanner.com
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
5,785
First Reported
19 Mar 2026
Last Reported
6 Aug 2026, 13:33

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS398324
Censys, Inc.
US US

Network Threat Assessment

2/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

613
Total IPs Monitored
85,901
Total Reports
140.1
Reports per IP

Network Context

This IP address belongs to Censys, Inc. (AS398324), which manages 613 IP addresses in our monitoring system. Out of these, 85,901 have been reported for suspicious activities, resulting in a network-wide threat level of 2/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

98 %

Global Threat Ranking

This IP is more threatening than 98% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 311,959 reported IPs worldwide

Threat Level 10/10 avg: 6.0 ++
Total Reports 5,785 avg: 18 ++

Network Comparison

Compared against 841 IPs in ASN 398324

Threat Level 10/10 network avg: 8.3 +
Total Reports 5,785 network avg: 227 ++
Network Censys, Inc. has overall threat level 2/10

Geographic Comparison

Compared against 65,768 IPs in US

Threat Level 10/10 country avg: 6.5 ++
Total Reports 5,785 country avg: 31 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

292,554 threat incidents tracked globally • Last 24h: 17,603 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    65,768 22.5%
  2. 02
    IN
    India IN
    49,068 16.8%
  3. 03
    CN
    China CN
    35,620 12.2%
  4. 04
    BR
    Brazil BR
    15,548 5.3%
  5. 05
    DE
    Germany DE
    10,497 3.6%
  6. 06
    PK
    Pakistan PK
    8,466 2.9%
  7. 07
    ID
    Indonesia ID
    8,403 2.9%
  8. 08
    SG
    Singapore SG
    8,311 2.8%
  9. 09
    RU
    Russia RU
    6,391 2.2%
  10. 10
    NL
    Netherlands NL
    6,295 2.2%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.4/10 Avg Threat
95% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

20 Related IPs
8.7/10 Avg Threat
91% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "66.132.172.175",
    "threat_level": 10,
    "confidence_score": 89,
    "total_reports": 5785,
    "country_code": "US",
    "isp_name": "Censys, Inc.",
    "asn": "398324",
    "first_reported": "2026-03-19 22:41:39",
    "last_reported": "2026-08-06 13:33:35",
    "exported_at": "2026-08-06T14:20:56+02:00",
    "source": "https://reportedip.com/ip/66.132.172.175/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.