IP Intelligence Briefing: 66.132.172.189
Date: 2026-06-18
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Provider: Censys, Inc. (ASN 398324)
- Geolocation: United States (MA, Boston)
- Network Role: Firewalled / No Services (no open ports or TLS/HTTP activity)
- Threat Indicators: No malicious activity detected (no blacklists, campaigns, or DNS anomalies).
- Ownership: Registered with ARIN, no abuse reports.
---
**2. Observation History**
- Last 30 Days:
- First observation: 2026-06-03 (subnet abuse density 0.4894, classified as "mixed").
- No persistent threats or malicious campaigns linked.
- Low confidence in geolocation and network stability.
---
**3. Relationships**
- Network Associations:
- Linked to CENSY network (likely a typo for Censys).
- DNS: 189.172.132.66.censys-scanner.com (Censys scanner hostname).
- No malicious relationships detected.
---
**4. Neighborhood Analysis**
- Subnet: 66.132.172.0/24
- Abuse Density: 48.94% (moderate risk).
- Neighbors:
- 14 active IPs in subnet (46 flagged as threats).
- Target IP (66.132.172.189) has low risk compared to peers.
---
**5. Recommendations**
- Monitor Subnet: The subnet has a moderate abuse density; investigate neighboring IPs for anomalies.
- Contextualize Use: The IP is associated with Censys, a cybersecurity company, likely used for network scanning.
- No Immediate Action: No malicious indicators detected, but maintain vigilance due to subnet risks.
---
Conclusion: 66.132.172.189 is a low-risk IP associated with Censys, likely used for legitimate scanning. While no direct threats are observed, the subnetβs moderate abuse density warrants further monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Censys, Inc. |
| ASN | AS398324 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 189.172.132.66.censys-scanner.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 189.172.132.66.censys-scanner.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 26% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:32 UTC |
| Last Seen | 2026-06-26 14:31:57 UTC |
| Profile Built | 2026-06-23 20:40:46 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.