## IP Intelligence Briefing: 66.132.172.207/32
Classification: Moderate Risk (Score: 50)
Date: 2026-06-26
Analysis Type: Full Intelligence Profile
---
Executive Summary
IP 66.132.172.207 is assigned to Censys, Inc. (ASN 398324) and resolves to the hostname 207.172.132.66.censys-scanner.com. The address exhibits a moderate risk score of 50 with mixed threat indicators. The subnet (66.132.172.0/24) shows elevated abuse density of 0.4839 with 45 threat-sibling IPs identified across 96 total neighbors. No active malicious services detected on this specific address.
---
Ownership and Geolocation
- Organization: Censys, Inc.
- ASN: 398324
- Location: United States (Florida, Miami)
- CIDR Block: 66.132.172.0/24
- Network Classification: Infrastructure (Firewalled / No Services)
- DNS Resolution: Forward confirmed to 207.172.132.66.censys-scanner.com
---
Threat Indicators
- Risk Score: 50 (Moderate)
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Threat Classification: No known campaigns, not Tor exit node, not identified as known attacker or spam source
- Operator Score: 0.2609 (Basic)
- Route Stability: Route changes observed (non-MoAS)
---
Network Neighborhood Analysis
The /24 subnet contains 96 IP addresses with the following distribution:
- High Risk: 0 addresses
- Medium Risk: 49 addresses
- Low Risk: 47 addresses
- Abuse Density: 0.4839 (Elevated)
- Threat Siblings: 45 IPs identified with threat indicators
Notable neighbor IPs include 66.132.172.32, 66.132.172.33, and 66.132.172.34β36, with risk scores ranging from 25β50.
---
Historical Observation Trends
Analysis of 21 observations reveals:
- Recent Activity: Multiple signals observed on 2026-06-26
- Subnet Density Fluctuation: Historical subnet abuse density observed at 0.2577, indicating variable threat activity across the block
- Geolocation Consistency: US-based classification maintained across observations
- Signal Persistence: Threat persistence days: 0; not persistently malicious
---
Relationship Graph
72 relationships identified, primarily:
- DNS associations to censys-scanner.com domain
- Multiple same-network relationships (CENSY)
---
Recommended Security Actions
Firewall Rules (Recommended for SOC Implementation):
```bash
# iptables
iptables -A INPUT -s 66.132.172.207 -j DROP
# nftables
nft add rule inet filter input ip saddr 66.132.172.207 drop
# nginx
deny 66.132.172.207;
```
Cloud Platform Integration:
- Cloudflare WAF: Block action with expression `ip.src eq 66.132.172.207`
- AWS WAF: Address set `["66.132.172.207/32"]` with description "IPDebrief risk 50"
---
Analyst Notes
While the IP address resolves to a Censys scanner hostname, the moderate risk score and subnet-level abuse density warrant defensive posturing. The absence of open services reduces immediate exploitability risk, but the neighborhood context suggests this subnet may be associated with broader reconnaissance or scanning activity. Monitor for correlation with other 66.132.172.0/24 addresses during threat hunting operations.
Status: Monitor / Block Recommended
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Censys, Inc. |
| ASN | AS398324 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 207.172.132.66.censys-scanner.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 207.172.132.66.censys-scanner.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 4 |
| geolocation | 19% | 2 | 2 |
| Overall | 22% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 08:59:20 UTC |
| Last Seen | 2026-06-26 18:11:31 UTC |
| Profile Built | 2026-06-26 09:19:01 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.