IP Intelligence Briefing: 102.129.60.117
Date: 2026-06-08
---
**1. Risk Profile**
- Risk Score: 55 (Moderate)
- Threat Indicators: No direct malicious activity detected (no known attackers, spam, or campaigns).
- Network Classification: Firewalled / No Services; residential IP flagged.
- Geolocation: South Africa (ZA), Gauteng, Vanderbijlpark (lat: -26.7, lon: 27.82).
---
**2. Ownership & Network**
- ASN: 327991 (Megasurf Wireless Internet CC, ZA).
- Subnet: 102.129.60.0/24.
- Neighborhood Risk: 13.5% abuse density.
- High-risk neighbors: 7 (e.g., 102.129.60.27: 80 risk score).
- Low-risk neighbors: 14.
- Mixed activity: Subnet contains both benign and potentially compromised IPs.
---
**3. DNS & Services**
- PTR Hostname: `ms-60-117.megasurf.co.za` (confirmed).
- DNSSEC: Valid.
- Email Reputation: SPF/DKIM records detected but no email abuse listed.
- Open Ports: None detected.
---
**4. Threat Observations (Last 30 Days)**
- 13 signals recorded:
- 8 threat feeds listed the IP (2 high-severity, 6 medium).
- DNSBL listings: 3/8 total lists (moderate risk).
- Routing stability: Unstable BGP path (route changes detected).
- No persistent malicious behavior (threat persistence: 0 days).
---
**5. Recommendations**
- Monitor subnet: High-risk neighbors (e.g., 102.129.60.27) may indicate broader compromise.
- Verify DNS: Investigate `ms-60-117.megasurf.co.za` for suspicious domains or CAA records.
- Block high-risk neighbors: Consider isolating IPs with >60 risk scores in the 102.129.60.0/24 subnet.
- Check for spoofing: Validate geolocation consistency (IP reported as South African, but RTT/RTT variance not available).
---
Next Steps: Correlate with internal logs, monitor DNS queries, and assess if the subnet requires network segmentation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Jacobus De Beer |
| ASN | AS327991 |
| Network Name | 102.129.60.0 - 102.129.60.255 |
| CIDR Block | 102.129.60.0/24 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ms-60-117.megasurf.co.za |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ms-60-117.megasurf.co.za |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 24% | 2 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 13% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 03:34:24 UTC |
| Last Seen | 2026-06-08 16:46:52 UTC |
| Profile Built | 2026-06-05 06:30:26 UTC |
| Data Freshness | Live |
| Signal Types | 11 |
| Total Observations | 11 |
Full dossier details are available via our API.