IPDebrief

66.132.224.93

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 66.132.224.93/32

Classification: LOW RISK | Analysis Date: Current | Source: IPDebrief

---

## EXECUTIVE SUMMARY

IP 66.132.224.93 is a Censys, Inc. infrastructure address associated with their scanner operations. The IP presents a low risk profile (score: 25), shows no active threat indicators, and is classified as firewalled with no open services. Intelligence indicates this is passive reconnaissance infrastructure, not an active threat actor endpoint.

---

## OWNERSHIP & GEOSLOCATION

Organization: Censys, Inc. (ASN: 398324)

Network: 66.132.224.0/24

Location: Miami, Florida, US (ARIN)

Registration: Available via RDAP

The IP is owned by Censys, a legitimate cybersecurity reconnaissance and scanning platform provider. The address resolves to the Censys scanner domain infrastructure.

---

## THREAT INDICATORS

IndicatorStatus
Known AttackerNo
Tor Exit NodeNo
Spam SourceNo
Blacklist Count0
Pulsedive RiskNot Available
Known CampaignsNone
DNSBL Listings1 of 8 total lists

Risk Score: 25 (Low Risk)

Abuse Confidence Score: Not Available

The IP has a minimal threat profile with no active malicious indicators. One DNSBL listing observed historically, but no current abuse signals.

---

## NETWORK ROLE & SERVICES

Infrastructure Type: Scanner/Probing Infrastructure

Services: Firewalled / No Services

Open Ports: None detected

TLS Certificate: Not Available

The IP presents no active services or open ports, indicating it is used for passive scanning operations rather than hosting malicious payloads or command-and-control infrastructure.

---

## DNS ANALYSIS

PTR Hostname: 93.224.132.66.censys-scanner.com

Forward Resolution: Confirmed

Hosted Domains: 0

Email Authentication: No SPF/DMARC records

DNS records confirm legitimate association with Censys scanner infrastructure.

---

## OBSERVATION HISTORY

Total Observations: 22 signals

Recent Activity: June 2026 (most recent)

Historical data shows consistent low-risk behavior over the observation period. One DNSBL listing observed in June 2024 with maximum severity rating. No escalation in threat activity observed over time.

---

## NETWORK RELATIONSHIPS

DNS Associations: 93.224.132.66.censys-scanner.com (primary)

Network Associations: Multiple entries for "CENSY" network

Relationship Count: 29 total relationships

The IP maintains strong DNS and network relationships within the Censys infrastructure, consistent with organized scanning operations.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 66.132.224.0/24

Sibling IPs: 31 total

Abuse Density: 0.5

Risk Distribution:

The /24 subnet shows mixed classification with 50% low-risk and 50% medium-risk siblings. This distribution is consistent with Censys' scanning infrastructure footprint, where multiple addresses are used for distributed reconnaissance.

---

## RECOMMENDED ACTIONS

Security Posture: Monitor, No Action Required

Recommended Actions:

Note: The IP represents legitimate scanning infrastructure. Blocking may impact legitimate security research operations.

---

## INTELLIGENCE CONCLUSION

IP 66.132.224.93 is Censys, Inc. scanner infrastructure with low-risk characteristics. The address shows no active threat indicators, no open services, and a stable risk profile. Historical data confirms consistent low-risk behavior. SOC analysts should maintain awareness of this as legitimate reconnaissance infrastructure rather than malicious threat actor assets.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionFL
CityMiami
Timezoneβ€”
Latitude37.75
Longitude-97.82

🏒 Ownership & Registration

OrganizationCensys, Inc.
ASNAS398324
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR93.224.132.66.censys-scanner.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames93.224.132.66.censys-scanner.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
8%
11
services
15%
22
ownership
20%
23
reputation
13%
12
geolocation
27%
23
Overall20%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-08 05:02:31 UTC
Last Seen2026-06-26 08:24:03 UTC
Profile Built2026-06-25 03:56:05 UTC
Data FreshnessLive
Signal Types21
Total Observations21
πŸ” 21 signal types Β· 21 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.