Significant Threat
IP 64.89.160.82, registered to Ghosty Networks LLC in the United Kingdom (AS205759), presents a high-risk threat profile with a threat level of 8/10 and a confidence score of 87%, driven primarily by sustained email spam activity detected through automated honeypot sensors from February through May 2026.
The address accumulated 1,099 total reports during this four-month window with an activity frequency rating of 8/10, indicating aggressive and continuous behavior. All 20 most recent incidents specifically attributed to email spam, confirming a persistent SMTP abuse pattern. The reporting volume—averaging approximately 275 reports per month—suggests automated, large-scale operations rather than opportunistic individual attempts. Automated honeypot sensors served as the sole detection mechanism, identifying systematic SMTP abuse originating from this UK-based address within Ghosty Networks LLC's infrastructure.
Email spam represents one of the most prevalent threats in the internet landscape, encompassing mass distribution of unsolicited messages, phishing campaigns targeting credentials and financial data, and malware delivery through embedded links or attachments. SMTP abuse allows threat actors to exploit the foundational email transmission protocol, blending malicious traffic with legitimate communications. Organizations running publicly accessible mail servers face immediate risks including inbox flooding, resource consumption, reputation damage to legitimate mail streams, and employee exposure to phishing content.
Site operators should implement multi-layered defenses against this and similar threats. Configuring fail2ban or equivalent intrusion prevention tools to automatically detect and block IPs exhibiting SMTP abuse patterns provides effective protection. Enforcing strict SMTP authentication and disabling open relay configurations eliminates common abuse vectors. Implementing SPF, DKIM, and DMARC email authentication protocols helps filter fraudulent senders. Deploying reputation-based filtering services that leverage real-time threat intelligence can proactively block known high-risk sources before they reach end users.