Substantial Risk
IP address 66.132.172.160 is a high-risk US address with a threat level of 8/10 that has generated 4,853 total abuse reports, driven predominantly by sustained hacking activity detected through automated honeypot sensors over a five-month window between March and July 2026.
The IP, registered to AS398324 and operated by Censys, Inc., carries a 92% confidence score based on reports from 20 independent automated honeypot sensors. Of the 20 most recent reported threat categories, 19 classify the activity as general hacking — encompassing intrusion attempts, exploitation attempts, and unauthorized access probing — while 1 report flags the address as an exploited host, suggesting the underlying infrastructure may itself be compromised and acting as an unwitting attack platform. The activity frequency of 8/10 indicates a high cadence of repeated connections, with observed patterns consistent with automated attack tools conducting connection-based probing and malware or exploit delivery attempts. The geographic concentration in the United States and the ASN association with a known internet-scanning organization warrants careful verification of the IP's current operational status, as ASN reassignments and shared infrastructure can occasionally misattribute legitimate research traffic.
Hacking activity of this volume and persistence typically reflects automated scanningToolchains that systematically target exposed services across vast IP ranges, probing for known vulnerabilities or misconfigurations. When paired with malware or exploit-related connection patterns, the risk extends beyond simple reconnaissance — the address may be actively attempting to deliver malicious payloads or establish footholds on unpatched systems. An exploited-host classification further suggests that even if the originating machine is itself compromised, it remains weaponized and dangerous to any reachable target. For organizations with internet-facing services, this combination of high report volume, sustained frequency, and dual-category threat signatures represents a credible and ongoing risk to perimeter security.