Analysis identified IP 64.125.19.131/32 as infrastructure associated with Zayo Bandwidth (ASN 6461, ABOVENET). Reverse DNS resolution confirmed the hostname ae2.er1.sea3.us.zip.zayo.com. Network service scans indicated the host was firewalled with no open ports. Reputation assessment returned a Low Risk score of 25. Threat indicators showed zero blacklist entries, and the address was not classified as a known attacker or spam source. DNS hygiene checks validated SPF and DMARC records.
Neighborhood data categorized the subnet 64.125.19.131/24 as mostly clean with an abuse density of 0.1818. Despite the low risk profile, the threat actor classification tagged the host as Suspicious Host because threat indicators were present but lacked specific campaign correlation. Behavioral monitoring recorded zero total incidents and no active attacker status. Control plane analysis indicated route instability for the BGP prefix 64.125.0.0/16 and one DNSBL listing. The recommended action was to monitor the IP due to its location in a mostly clean neighborhood, with an overall confidence rating of Very Low.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Zayo Bandwidth |
| ASN | AS6461 |
| Network Name | ABOVENET |
| CIDR Block | 64.124.190.0/23 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ae2.er1.sea3.us.zip.zayo.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | ae2.er1.sea3.us.zip.zayo.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-09 07:52:24 UTC |
| Last Seen | 2026-09-20 06:56:59 UTC |
| Profile Built | 2026-09-23 01:06:21 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 32 |
Full dossier details are available via our API.