# INTELLIGENCE BRIEFING: 64.89.161.80/32
## Executive Summary
IP address 64.89.161.80 presents a moderate risk profile (score: 40) with no active services, firewalled posture, and minimal operator threat profile. The IP is located in Boston, MA, US, operating within ASN 205759 with BGP prefix 64.89.161.0/24.
## Risk Assessment
- Overall Risk Score: 40 (Moderate)
- Reputation: Moderate Risk
- Operator Score: 0.1304 (Minimal)
- Blacklist Status: Listed on 2 of 8 DNSBLs (high severity)
- Campaign Association: No known campaigns identified
- Attacker Classification: Not flagged as known attacker, spam source, or Tor exit node
## Network Characteristics
- Services: No open ports; service classification: "Firewalled / No Services"
- DNS: DNSSEC valid; no PTR hostnames; no forward resolution
- Geolocation: United States, Massachusetts, Boston (accuracy radius unconfirmed)
- Network Path: Transit networks include Comcast and GTT; hop count: 15
- Route Stability: Not stable (route changes observed in 30-day period)
## Historical Signals
Nine observations recorded with recent activity from July 26, 2026:
- DNSSEC validation confirmed across observations
- DNS blacklist listings detected with high severity categories
- Geographic signals consistently resolving to United States via MaxMind Geolite2
- No persistent malicious threat persistence days observed
- No honeypot hits or enumeration strikes recorded
## Neighborhood Analysis
Subnet 64.89.161.0/24 contains 31 sibling IPs:
- Risk Distribution: 0 high, 12 medium, 19 low
- Abuse Density: 0
- Notable Neighbors: 64.89.161.8 (60), 64.89.161.82 (60), 64.89.161.93 (65)
- Inherited Risk: 0
- Classification: No subnet-level threat indicators
## Recommended Actions
Firewall rules recommended for deployment:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 64.89.161.80 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 64.89.161.80 drop` |
| nginx | `deny 64.89.161.80;` |
| pfSense | `64.89.161.80/32` |
| Cloudflare WAF | Block IP with expression `ip.src eq 64.89.161.80` |
| AWS WAF | Add IP address to blacklist with description "IPDebrief risk 40" |
## SOC Analyst Notes
- IP is currently firewalled with no accessible services; active scanning may be limited
- DNSBL listings suggest prior reputation issues; monitor for renewed activity
- No direct relationships identified to other malicious entities
- Neighborhood shows mixed risk profile with several medium-risk siblings
- Recommend blocking at perimeter with monitoring for future service openings or behavioral changes
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Ghosty Networks LLC |
| ASN | AS205759 |
| Network Name | GHOSTY-NETWORKS-LU |
| CIDR Block | 64.89.160.0/23 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | — |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS205759 |
| Network Prefix | 64.89.161.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 02:47:45 UTC |
| Last Seen | 2026-09-02 23:46:28 UTC |
| Profile Built | 2026-09-02 23:50:40 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 64.89.161.80
Who owns the IP address 64.89.161.80?
64.89.161.80 is registered to Ghosty Networks LLC. The address falls within the 64.89.160.0/23 network block. Registration is held at ARIN.
Where is 64.89.161.80 located?
Geolocation data places 64.89.161.80 in Luxembourg. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 64.89.161.80 malicious or safe?
64.89.161.80 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 64.89.161.80?
Responsive ports observed on 64.89.161.80 include 3389. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.