IP Address

66.56.215.97

IPv4 Public
US US
AS11426
TWC-11426-CAROLINAS
163 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
73% Confidence
163 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
US
US Location
TWC-11426-CAROLINAS ASN 11426
163 Reports
Honeypot Data Source

Critical Threat

IP 66.56.215.97 is a high-risk address operating from the United States within the TWC-11426-CAROLINAS autonomous system that has been flagged by automated honeypot sensors as an exploited host conducting active hacking activity, with 163 total abuse reports filed against this single address. The threat assessment reaches a critical 10 out of 10 score with an activity frequency rating of 8 out of 10, indicating sustained and persistent malicious behavior over approximately seven months of documented observation from October 2025 through May 2026. Community reports and sensor data converge on two dominant threat categories: exploited host activity accounting for the highest volume of recent reports, followed closely by general hacking intrusion attempts, suggesting this IP represents a compromised system being weaponized by threat actors without the owner's knowledge.

The 163 total reports filed against 66.56.215.97 originate exclusively from 20 automated honeypot sensors, lending credibility to the detection through consistent cross-sensor observation rather than isolated incidents. Detection signatures from network monitoring systems, specifically Suricata-based alerting, identified the use of potentially unsafe SMBv1 protocol connections, which are commonly associated with malware propagation and exploitation frameworks in real-world attack campaigns. The AS11426 network operated by TWC-11426-CAROLINAS routes this traffic, placing the compromised infrastructure within a major United States telecommunications provider commonly serving residential and business customers in the Carolinas region. The 73% confidence score reflects some uncertainty typical of automated threat classification systems while still establishing a strong evidentiary basis for the high-risk determination.

The dominant exploited host classification indicates that 66.56.215.97 has likely been compromised through malware infection, vulnerability exploitation or unauthorized access, transforming it into an unwitting attack platform controlled by external threat actors. SMBv1 protocol usage detected by sensors is a well-documented attack vector associated with ransomware delivery, lateral movement and wormable exploit propagation including historical campaigns such as WannaCry and NotPetya. The hacking activity category encompasses the intrusion attempts, vulnerability exploitation and unauthorized access attempts that originate from this compromised system, meaning defenders may encounter this IP attempting to scan their external services, brute-force credentials or exploit known vulnerabilities. A threat frequency rating of 8 out of 10 confirms this is not sporadic behavior but rather sustained offensive operations against multiple targets.

More threatening than 97% of monitored IPs

Threat Categories

Exploited Host 30
Hacking 19

Technical Details

This IP belongs to a compromised system being used as an attack platform without the owner's knowledge.

Recommended Mitigations

Block the IP and consider notifying the hosting provider or system owner about the compromise.

Moderate Network Risk

The network hosting this IP (ASN 11426, operated by TWC-11426-CAROLINAS) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 8/10 High
Confidence Score 59% High Confidence

Confidence History

20. Jan 2026 - 22. May 2026
73% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Exploited Host Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Exploited Host Honeypot x5 75%
Exploited Host Honeypot x4 75%
Exploited Host Honeypot x2 75%
Exploited Host Honeypot x5 75%
Exploited Host Honeypot x4 75%
Exploited Host Honeypot x5 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot x3 75%
Exploited Host Honeypot x5 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%

Technical Details

Basic Information

IP Address
66.56.215.97
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
AS11426
ISP
TWC-11426-CAROLINAS

DNS Information

Reverse DNS
syn-066-056-215-097.res.spectrum.com
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
163
First Reported
27 Oct 2025
Last Reported
22 May 2026, 02:12

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS11426
Charter Communications Inc
US US

Network Threat Assessment

5/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

25
Total IPs Monitored
439
Total Reports
17.6
Reports per IP

Network Context

This IP address belongs to Charter Communications Inc (AS11426), which manages 25 IP addresses in our monitoring system. Out of these, 439 have been reported for suspicious activities, resulting in a network-wide threat level of 5/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

97 %

Global Threat Ranking

This IP is more threatening than 97% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 775,148 reported IPs worldwide

Threat Level 10/10 avg: 5.9 ++
Total Reports 163 avg: 9 ++

Network Comparison

Compared against 176 IPs in ASN 11426

Threat Level 10/10 network avg: 6.0 ++
Total Reports 163 network avg: 10 ++
Network TWC-11426-CAROLINAS has overall threat level 5/10

Geographic Comparison

Compared against 137,062 IPs in US

Threat Level 10/10 country avg: 6.4 ++
Total Reports 163 country avg: 19 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

705,204 threat incidents tracked globally • Last 24h: 46,668 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    137,062 19.4%
  2. 02
    BR
    Brazil BR
    109,634 15.5%
  3. 03
    IN
    India IN
    76,865 10.9%
  4. 04
    CN
    China CN
    43,408 6.2%
  5. 05
    SC
    SC SC
    29,200 4.1%
  6. 06
    NL
    Netherlands NL
    16,612 2.4%
  7. 07
    AR
    Argentina AR
    16,087 2.3%
  8. 08
    DE
    Germany DE
    16,072 2.3%
  9. 09
    PK
    Pakistan PK
    15,455 2.2%
  10. 10
    CO
    Colombia CO
    15,083 2.1%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9/10 Avg Threat
75% Avg Confidence
18 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "66.56.215.97",
    "threat_level": 10,
    "confidence_score": 73,
    "total_reports": 163,
    "country_code": "US",
    "isp_name": "TWC-11426-CAROLINAS",
    "asn": "11426",
    "first_reported": "2025-10-27 12:59:14",
    "last_reported": "2026-05-22 02:12:12",
    "exported_at": "2026-09-22T18:59:49+02:00",
    "source": "https://reportedip.com/ip/66.56.215.97/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.