Notable Threat
IP 65.49.20.66 presents a high-risk threat profile with a threat level of 8 out of 10, backed by 615 abuse reports from automated honeypot sensors and a confidence score of 87 percent. This address, originating from Hurricane Electric's AS6939 network infrastructure in the United States, has been actively targeting systems since September 2025, with the most recent activity recorded in June 2026.
The overwhelming majority of reported threat categories consist of hacking activity, accounting for 19 of the 20 total categorized reports, while a single web application attack was also logged. Detection data from 20 separate automated honeypot sensors captured connection attempts, web application probing, and notably a Suricata alert indicating an SSH session in progress on an unusual port. The eight-out-of-ten activity frequency score underscores a consistent, sustained pattern of malicious behaviour over approximately nine months, making this IP reputation notably poor for any organization reviewing whether to block this address.
The dominant hacking classification encompasses intrusion attempts, vulnerability exploitation, and unauthorized access efforts against exposed services. Web application attacks further indicate interest in exploiting weaknesses such as injection flaws, file inclusion vulnerabilities, or other OWASP Top 10 issues present in publicly accessible applications. The detection of SSH activity on an unconventional port strongly suggests the threat actor is attempting to evade standard detection by running the protocol on a non-standard port, likely as part of a credential-brute-forcing campaign or as an initial foothold to establish persistent access.
Site operators should block or heavily restrict inbound traffic from IP 65.49.20.66 at the network perimeter, implementing automated blocking through defensive tools such as fail2ban or equivalent rate-limiting solutions. Port scanning and service enumeration attempts can be mitigated by disabling unnecessary services, restricting SSH access to known IP ranges, and enforcing certificate-based authentication where possible. Deploying a web application firewall will add a critical layer of defence against the probing and web-based exploitation patterns observed. Regular security audits, prompt patching cycles, and monitoring for unusual outbound connections from internal hosts remain essential practices to limit exposure to similar threats originating from high-risk IP addresses.