# IP Intelligence Briefing: 66.132.186.205/32
## Executive Summary
IP address 66.132.186.205/32 presents a moderate risk profile (risk score: 50) with no active threat indicators. The IP is associated with Censys, Inc. (ASN: 398324) and operates within a high-abuse density subnet (66.132.186.0/24). Current analysis indicates the IP is firewalled with no active services.
## Ownership and Network Context
- Organization: Censys, Inc.
- ASN: 398324
- Geolocation: United States, Florida (Miami region)
- Classification: Infrastructure/Scanner (not CDN, hosting, VPN, or proxy)
- DNS Resolution: 205.186.132.66.censys-scanner.com
- Route Stability: False (route changes detected in 30-day window)
## Risk Assessment
- Overall Risk Score: 50 (Moderate Risk)
- DNSBL Listings: 2 of 8 total lists
- Abuse Density: Subnet classified as high_abuse (0.5833 density)
- Operator Score: 0.1304 (Minimal)
- Known Threats: None identified (not Tor exit, not known attacker, not spam source)
## Neighborhood Analysis (66.132.186.0/24)
The IP resides in a subnet with elevated abuse characteristics:
- Total Subnet IPs: 48
- Active Siblings: 31
- Threat-Classified Siblings: 28
- Risk Distribution: High (0), Medium (28), Low (19)
## Current Services and Ports
- Open Ports: None detected
- Service Status: Firewalled / No Services
- TLS/HTTP: No active service signatures
## Observation History
Recent intelligence signals include:
- DNSBL listings observed with high severity classification
- Operator score remained minimal (0.1304)
- Geovalidation flagged implausible location data
- No persistent malicious activity detected (threat persistence: 0 days)
## Threat Indicators
- Campaign Correlation: None
- Certificate Matches: 0
- Threat Feeds: No active indicators
## Recommended Security Actions
Based on risk profile and neighborhood context, the following blocking rules are recommended:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 66.132.186.205 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 66.132.186.205 drop` |
| nginx | `deny 66.132.186.205;` |
| pfSense | `66.132.186.205/32` |
| Cloudflare WAF | Block IP with filter expression `ip.src eq 66.132.186.205` |
| AWS WAF | Add IP `66.132.186.205/32` to blocked list |
## Analysis Notes
While the IP shows no active malicious behavior, its subnet context (high abuse density, 28 threat siblings) and DNSBL listings warrant monitoring. The IP appears to be part of Censys infrastructure, which may be conducting security research or vulnerability scanning activities. Consider implementing rate limiting or allowing only during business hours if legitimate traffic is expected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Censys, Inc. |
| ASN | AS398324 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 205.186.132.66.censys-scanner.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 205.186.132.66.censys-scanner.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 11% | 1 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 22:11:25 UTC |
| Last Seen | 2026-06-25 21:31:43 UTC |
| Profile Built | 2026-06-25 21:49:02 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.