IP Address

64.89.161.198

IPv4 Public
US US
ISP Associates
230 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
6/10 Threat
96% Confidence
230 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Moderate Risk
US
US Location
ISP Associates ISP
230 Reports
Mixed Data Source

Cautionary Risk

IP 64.89.161.198, registered to ISP Associates in the United States, is a medium-high risk address associated with 230 abuse reports and a confidence score of 96%. The dominant threat activity is general hacking probes, accounting for 18 of the most recent reports, alongside bad web bot behavior, WordPress configuration exposure attempts, unauthorized WP-Cron execution, and isolated DDoS and web application attack signatures. With an activity frequency rated 8 out of 10, this IP demonstrates persistent, automated scanning behavior directed at web infrastructure.

Detection data draws from 16 automated honeypot sensors and 4 community-based reports, all timestamped to February 2026. Abstracted attack-pattern logs reveal repeated automated scanner detections targeting NGINX servers, with specific focus on suspicious backup-related POST requests and unauthorized WP-Cron execution attempts. The IP also generated multiple attack connection events and web application probe activities consistent with vulnerability scanning toolchains. The concentration of honeypot hits across multiple sensor types indicates this is not opportunistic noise but deliberate, systematic reconnaissance against exposed web services.

The hacking category encompasses intrusion attempts, vulnerability exploitation, and unauthorized access probes—behaviors confirmed by the observed scanner signatures and POST requests targeting backup files and cronjob endpoints. For site operators running WordPress, unauthorized cron execution can facilitate privilege escalation, data exfiltration, or secondary payload delivery. When combined with WP Config Exposure attempts and generic web application probes, this IP profile suggests an actor preparing for or conducting automated compromise campaigns against misconfigured or unpatched web servers rather than random scanning.

Operators should block or rate-limit this IP at the firewall or load balancer level given the sustained activity and diverse attack vector profile. Enforcing strict access controls on wp-cron.php, renaming or restricting access to sensitive backup file paths, and implementing fail2ban or equivalent intrusion prevention rules can disrupt the observed automation patterns. Web application firewalls with bot management capabilities provide an additional layer of defense against the bad web bot activity and scanner signatures associated with this address.

More threatening than 52% of monitored IPs

Threat Categories

Hacking 19
Bad Web Bot 4
Web App Attack 3
DDoS Attack 2
WP Cron Abuse 2
WP Config Exposure 2

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 0) with generally good reputation. The ISP ISP Associates maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 6/10 Medium
High
Activity Frequency 8/10 High
Confidence Score 57% High Confidence

Confidence History

3. Feb 2026 - 23. Feb 2026
96% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (21)

Date Categories Source Confidence
WP Config Exposure Hacking WP Cron Abuse +2 Community x3 75%
Bad Web Bot Community 75%
Bad Web Bot Community 75%
Hacking Honeypot x2 75%
Bad Web Bot WP Config Exposure Hacking +2 Community x3 75%
Hacking Honeypot 75%
Hacking Honeypot x2 75%
Hacking Web App Attack Honeypot x6 75%
Web App Attack Hacking Honeypot x11 75%
Hacking Honeypot x10 75%
Hacking Honeypot x16 75%
Hacking Honeypot x10 75%
Hacking Honeypot x19 75%
Hacking Honeypot x24 75%
Hacking Honeypot x29 75%
Hacking Honeypot x18 75%
Hacking Honeypot x32 75%
Hacking Honeypot x35 75%
Hacking Honeypot 75%
Hacking Honeypot x2 75%
Hacking Web App Attack Honeypot x3 75%

Technical Details

Basic Information

IP Address
64.89.161.198
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
Unknown
ISP
ISP Associates

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
230
First Reported
3 Feb 2026
Last Reported
23 Feb 2026, 02:16

Comparative Analysis

How this IP compares to others in our threat intelligence database

52 %

Global Threat Ranking

This IP is more threatening than 52% of all IPs in our database.

Above Average Threat

Global Comparison

Compared against 229,429 reported IPs worldwide

Threat Level 6/10 avg: 5.6 =
Total Reports 230 avg: 21 ++

Geographic Comparison

Compared against 44,186 IPs in US

Threat Level 6/10 country avg: 6.1 =
Total Reports 230 country avg: 38 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

214,990 threat incidents tracked globally • Last 24h: 17,714 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    44,178 20.5%
  2. 02
    IN
    India IN
    34,935 16.2%
  3. 03
    CN
    China CN
    28,628 13.3%
  4. 04
    BR
    Brazil BR
    11,590 5.4%
  5. 05
    DE
    Germany DE
    8,150 3.8%
  6. 06
    SG
    Singapore SG
    6,991 3.3%
  7. 07
    ID
    Indonesia ID
    6,382 3%
  8. 08
    PK
    Pakistan PK
    5,791 2.7%
  9. 09
    RU
    Russia RU
    5,349 2.5%
  10. 10
    NL
    Netherlands NL
    4,896 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "64.89.161.198",
    "threat_level": 6,
    "confidence_score": 96,
    "total_reports": 230,
    "country_code": "US",
    "isp_name": "ISP Associates",
    "asn": "0",
    "first_reported": "2026-02-03 00:35:00",
    "last_reported": "2026-02-23 02:16:15",
    "exported_at": "2026-06-25T05:53:25+02:00",
    "source": "https://reportedip.de/ip/64.89.161.198/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.