# IP Intelligence Briefing: 66.132.186.183/32
## Executive Summary
IP 66.132.186.183 is a Censys, Inc. infrastructure address classified as Moderate Risk with a risk score of 40. The IP is associated with Censys scanner operations and shows no evidence of malicious activity. Despite a subnet-level abuse density of 0.5833, this specific IP maintains a clean threat profile with no active threat indicators.
## Ownership and Network Classification
- Organization: Censys, Inc. (ASN: 398324)
- Geolocation: Chicago, Illinois, US
- CIDR Block: 66.132.186.0/24
- Network Role: Firewalled / No Services Detected
- Registration: ARIN-registered infrastructure
## Technical Profile
- DNS Resolution: 183.186.132.66.censys-scanner.com (Forward confirmed)
- PTR Hostname: 183.186.132.66.censys-scanner.com
- Open Ports: None detected
- TLS Certificate: Not present
- DNSSEC: Validated
- DNSBL Listings: 1 of 8 total lists (dnsblListedCount)
## Threat Indicators
- Abuse Confidence Score: Not available
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
## Behavioral Observations
- Threat Observation Count: 1
- Honeypot Hits: 0
- Campaign Correlation: None detected
- Certificate Matches: 0
## Subnet Analysis (66.132.186.0/24)
- Total Siblings: 48 IPs
- Active Siblings: 36
- Threat Siblings: 28
- Abuse Density: 0.5833 (High abuse classification)
- Risk Distribution: 0 high, 47 medium, 0 low
- Inherited Risk Score: 23
Notable neighbor risk scores include:
- 66.132.186.162: Risk 65, Authority 60
- 66.132.186.161: Risk 50, Authority 60
- 66.132.186.163: Risk 50, Authority 60
## Relationship Graph
The IP maintains 30 documented relationships, primarily:
- DNS Associations: Multiple entries to 183.186.132.66.censys-scanner.com
- Network Associations: Multiple "Same Network" relationships to CENSY network infrastructure
- No external organizational or hosting provider relationships beyond Censys
## Historical Signals (18 Observations)
Recent signal timeline indicates:
- 2026-06-18: Subnet classified as "high_abuse" with abuse density 0.5833
- 2026-06-18: Geolocation signals confirmed US (Chicago region)
- 2026-06-18: Operator score 0.2609 (Basic classification)
- 2026-06-03: Network role confirmed as non-hosting, non-cloud infrastructure
## Risk Assessment
The IP presents a moderate risk profile (40/100) characteristic of legitimate Censys scanner infrastructure. While the subnet shows elevated abuse density (0.5833) with 28 threat-sibling IPs, this specific address shows no malicious indicators. The high authority score (60) across neighboring IPs suggests legitimate operational infrastructure rather than abuse.
## Recommended Actions
- Traffic Allow: Permissible for Censys scanning operations
- Firewall Rules: No blocking recommended
- Monitoring: Standard monitoring sufficient
- Threat Intelligence: No threat indicators detected
## SOC Analyst Notes
This IP belongs to Censys, Inc. infrastructure used for security scanning operations. The moderate risk score reflects the subnet's general abuse density rather than malicious activity from this specific address. No immediate defensive action required unless unusual traffic patterns emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Censys, Inc. |
| ASN | AS398324 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 183.186.132.66.censys-scanner.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 183.186.132.66.censys-scanner.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:32 UTC |
| Last Seen | 2026-06-26 18:11:32 UTC |
| Profile Built | 2026-06-23 20:25:18 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.