64.89.161.12

Classification: Malicious

64.89.161.12 is a malicious IP address. Reported by 4 threat sources, last seen 2026-09-05. Network: AS205759 Ghosty Networks LLC.

Current activity

  • Known attacker โ€” Seen launching attacks over the Internet.
  • Known scanner โ€” Seen scanning hosts over the Internet.
  • VPN node โ€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Bruteforce Blocklist.net.ua 2026-07-31 16:00:36 2026-09-05 16:23:47 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 16:25:48 2026-09-04 16:25:48 attacker malicious-activity
Mail Spammer Blocklist.de 2026-08-15 12:01:46 2026-08-24 12:02:53 attacker malicious-activity
IMAP Attacker Blocklist.de 2026-08-15 11:01:33 2026-08-24 11:02:30 attacker malicious-activity
VPN IPWhois.io 2026-07-31 16:00:36 2026-07-31 16:00:36 anonymization vpn
Mail Spammer AbuseIPDB 2026-07-22 16:30:29 2026-07-31 14:19:32 attacker malicious-activity
Bruteforce AbuseIPDB 2026-07-22 14:05:09 2026-07-31 14:19:32 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-07-24 06:00:09 2026-07-31 01:46:03 attacker malicious-activity
Hacking AbuseIPDB 2026-07-23 14:45:02 2026-07-29 07:04:56 attacker malicious-activity
Port Scanner AbuseIPDB 2026-07-24 06:00:02 2026-07-26 10:34:37 anomalous-activity attacker malicious-activity reconnaissance
SSH Attacker AbuseIPDB 2026-07-24 10:32:43 2026-07-26 06:00:00 attacker malicious-activity
DDoS Attacker AbuseIPDB 2026-07-24 10:32:43 2026-07-25 14:34:50 attacker malicious-activity
Malicious Host AbuseIPDB 2026-07-24 08:00:53 2026-07-24 08:00:53 attacker compromised malicious-activity

Tags

abuse attacker imap pop3 sasl bot mail spam

Whois information

AS name
AS205759 Ghosty Networks LLC
Registrant
Ghosty Networks LLC
City
Nommern
Postal code
9184
Country
LU โ€” Luxembourg ๐Ÿ‡ฑ๐Ÿ‡บ
First indexed
2026-07-31 16:00:36
Last updated
2026-09-05 16:23:47