# IPDEBRIEF INTELLIGENCE BRIEFING
IP Address: 64.89.160.73/32
Classification: Moderate Risk (50/100)
Date of Assessment: 2026-07-24
## Executive Summary
IP 64.89.160.73 belongs to Ghosty Networks LLC (ASN 205759) and presents a moderate risk profile (score: 50). The IP is geofenced as Boston, US but exhibits geolocation inconsistencies across data sources. The subnet (64.89.160.0/24) demonstrates elevated abuse density (0.3), with 12 high-risk and 15 medium-risk neighboring IPs. No active threat indicators or open services were detected.
## Network Ownership & Infrastructure
- Organization: Ghosty Networks LLC
- ASN: 205759
- CIDR Block: 64.89.160.0/23
- RIR: ARIN
- Geolocation: US-MA (Boston) with conflicting reports from Luxembourg and Kansas in historical observations
- Network Classification: Firewalled / No Services detected
## Threat Assessment
The IP shows no direct threat indicators:
- Not a known attacker or spam source
- Not a Tor exit node
- No active threat campaigns correlated
- Blacklist count: 0
However, control plane data reveals the IP is listed on 2 of 8 DNSBLs, indicating prior reputation issues. The operator score (0.1304) is classified as "Minimal," suggesting limited malicious operator activity.
## Neighborhood Analysis
The /24 subnet (64.89.160.0/24) contains 40 sibling IPs with concerning abuse patterns:
- Abuse Density: 0.3 (30%)
- Risk Distribution: 12 high-risk, 15 medium-risk, 13 low-risk IPs
- Notable High-Risk Neighbors: 64.89.160.22, 64.89.160.23, 64.89.160.25, 64.89.160.26, 64.89.160.28, 64.89.160.30, 64.89.160.33, 64.89.160.34, 64.89.160.36, 64.89.160.37, 64.89.160.38, 64.89.160.40, 64.89.160.135
One historical observation correlated with AS12036 (isp associates inc. dba dixie-net, Ripley, MS) with reputation 0 and threat flags active.
## Behavioral Indicators
- Ownership Stability: No changes recorded; persistently stable
- Threat Persistence: 0 days; not persistently malicious
- Network Role: Infrastructure type undetermined; no CDN, hosting, or proxy indicators
- Traceroute: 15 hops via Comcast and GTT transit networks
## Recommended Actions
Based on the moderate risk profile and neighborhood context, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 64.89.160.73 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 64.89.160.73 drop
```
nginx:
```
deny 64.89.160.73;
```
Cloudflare WAF:
```json
{
"description": "Block 64.89.160.73 — IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 64.89.160.73"
}
}
```
AWS WAF:
```json
{
"Addresses": ["64.89.160.73/32"],
"Description": "IPDebrief risk 50"
}
```
## Intelligence Assessment
The IP should be treated with caution due to neighborhood abuse density and DNSBL listings. While no active malicious behavior was observed at the time of assessment, the subnet's high-risk neighbor concentration suggests potential for coordinated abuse. Monitor for changes in threat indicators and geolocation consistency.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Ghosty Networks LLC |
| ASN | AS36680 |
| Network Name | GHOSTY-NETWORKS-LU |
| CIDR Block | 64.89.160.0/23 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS36680 |
| Network Prefix | 64.89.160.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 24% | 2 | 2 |
| reputation | 17% | 1 | 2 |
| geolocation | 24% | 2 | 2 |
| Overall | 21% | 9 | 10 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 13:03:47 UTC |
| Last Seen | 2026-09-29 20:37:30 UTC |
| Profile Built | 2026-09-25 02:20:20 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 64.89.160.73
Who owns the IP address 64.89.160.73?
64.89.160.73 is registered to Ghosty Networks LLC. The address falls within the 64.89.160.0/23 network block. Registration is held at ARIN.
Where is 64.89.160.73 located?
Geolocation data places 64.89.160.73 in Frankfurt, Diekirch, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 64.89.160.73 malicious or safe?
64.89.160.73 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.