Significant Threat
IP 65.49.1.66 is a high-risk address associated with sustained hacking activity, accumulating 543 abuse reports from honeypot sensors over approximately 11 months. With a threat level of 8/10 and activity frequency rated 8/10, this IP demonstrates a consistent pattern of intrusion attempts, vulnerability exploitation, and unauthorized access scanning targeting exposed services. The volume and persistence of reports indicate deliberate, automated hostile reconnaissance against internet-facing infrastructure.
Automated honeypot sensors across 20 distinct detection points recorded the majority of activity, supplemented by community reports, spanning from August 2025 through June 2026. The address originates from Hurricane Electric's AS6939 network in the United States, a large transit provider hosting diverse customer traffic. The reported threat categories include general hacking attempts, IoT and industrial control system targeting, and web application probing, with associated detection rules flagging application-layer protocol anomalies consistent with service enumeration. This combination suggests the operator is running automated scanning toolkits attempting to identify and exploit both network misconfigurations and vulnerable connected devices.
The dominant hacking activity represents coordinated exploitation attempts against internet-facing services, including vulnerability scanning and authentication attack patterns. Combined with detected IoT targeting and protocol-level anomalies, this IP poses material risk to unpatched systems, default-configured connected devices, and web applications lacking proper defensive controls. The confidence score of 82% reflects strong evidentiary support for malicious intent based on observed behavioral patterns across multiple independent sensors.
Site operators with exposed services should implement layered defensive measures including blocking or rate-limiting at the network perimeter, deploying intrusion detection tools such as fail2ban to automatically respond to automated attack patterns, enforcing strong authentication with multi-factor authentication on all remote access channels, and maintaining current patching cycles with regular scanning for vulnerable configurations that this scanning activity may be probing for.