## Intelligence Briefing: IP 66.132.195.69
Classification: Moderate Risk (Score: 50)
Date: 2026-06-18
Status: Operational Infrastructure
Ownership and Network Context
IP 66.132.195.69 is registered to Censys, Inc. (ASN: 398324), a legitimate security scanning and intelligence platform. The address resolves to hostname 69.195.132.66.censys-scanner.com, confirming operation as part of Censys's scanning infrastructure. Geographic analysis places the IP in Miami, FL, US with a 2,500 km accuracy radius.
Network Role and Services
- Infrastructure Type: Firewalled / No Services Detected
- Open Ports: None
- CDN/Proxy/VPN/Hosting: No
- Cloud Infrastructure: No
- Anycast: No
The IP shows no active services, consistent with a passive scanning or control-plane role within Censys infrastructure.
Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Campaign Correlation: None
- Threat Persistence: 0 days
- Persistently Malicious: No
No active threat indicators or malicious behavior observed. The IP maintains a clean reputation profile with zero blacklist hits.
Subnet Analysis
The IP resides in 66.132.195.0/24 subnet with the following characteristics:
- Total Siblings: 96
- Active Siblings: 70
- Threat Siblings: 45
- Abuse Density: 0.4688 (moderate)
- Risk Distribution: 0 high, 60 medium, 35 low risk
- Classification: Mixed
The subnet exhibits moderate abuse density typical of scanning infrastructure, with a majority of sibling IPs carrying medium risk scores (25-50).
Historical Observations
Analysis of 21 observations indicates:
- Ownership Stability: No ownership changes detected
- Threat Observation Count: 1
- Recent Activity: Consistent Censys infrastructure assignment
- DNS Resolution: Stable to censys-scanner.com domains
- Operator Score: 0.2609 (Basic classification)
No degradation in risk profile over the observation period.
Relationships and Associations
- DNS Associations: 69.195.132.66.censys-scanner.com
- Network Affiliations: CENSY network
- Total Relationships: 34
All associations confirm legitimate Censys infrastructure operations.
Recommended Actions
No blocking recommended. The IP is associated with legitimate security research infrastructure (Censys). If traffic is observed:
- Allowed: Permit inbound/outbound traffic on standard scanning ports (TCP 80, 443, 53)
- Monitored: Log all interactions for threat intelligence correlation
- Blocked: No action required unless correlated with other malicious indicators
Summary
IP 66.132.195.69 is operational Censys scanner infrastructure with moderate risk scoring due to subnet-level activity patterns. No direct threat indicators. Traffic should be permitted and monitored for intelligence purposes rather than blocked. The IP maintains a clean reputation with zero blacklist associations and no evidence of malicious activity.
Threat Level: LOW (Infrastructure-Associated)
Recommended Action: Monitor / Allow
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Censys, Inc. |
| ASN | AS398324 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 69.195.132.66.censys-scanner.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 69.195.132.66.censys-scanner.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 26% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:33 UTC |
| Last Seen | 2026-06-26 18:11:32 UTC |
| Profile Built | 2026-06-23 20:35:13 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.