# IP Intelligence Briefing: 102.251.14.6/32
## Executive Summary
IP address 102.251.14.6 presents as a moderate-risk residential connection in Durban, South Africa, with no active threat indicators detected. The IP is associated with Telkom ADSL infrastructure and shows signs of being actively managed through firewalling. No malicious activity was observed in the neighborhood or historical data.
## Network Ownership and Geolocation
- ASN: 37457
- Organization: Chris Aucamp
- CIDR Block: 102.251.0.0/16 (Afrinic RIR)
- Country: South Africa (ZA)
- Region: KwaZulu-Natal
- City: Durban
- Geolocation Confidence: High (consensus verified with plausible coordinates at 9,455 km validation distance)
## Technical Profile
- Service Status: No open services detected; classified as "Firewalled / No Services"
- Open Ports: None observed
- DNS Resolution: Forward confirmed to 8ta-251-14-06.telkomadsl.co.za
- PTR Record: 8ta-251-14-06.telkomadsl.co.za
- Email Authentication: SPF and DMARC records present
- Network Classification: Residential/Consumer ADSL line; not cloud, CDN, VPN, proxy, or hosting infrastructure
- Tor Exit Node: No
## Threat Assessment
- Risk Score: 55 (Moderate Risk)
- Abuse Confidence Score: Not available
- Blacklist Status: 0 blacklists
- DNSBL Status: Listed on 3 of 8 DNSBL feeds
- Known Campaigns: None associated
- Tor/Proxy Activity: Not detected
- Spam Source: Not flagged
## Neighborhood Context
- Subnet: 102.251.14.6/24
- Abuse Density: 0 (clean classification)
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
- Risk Distribution: No high or medium risk neighbors detected
## Historical Trend Analysis
- Observations: 18 total signals collected
- Last Observed: 2026-07-29
- Threat Persistence: 0 days (no persistent malicious activity detected)
- Ownership Changes: 0 (stable ownership)
- Route Stability: Route changes observed (not stable)
- Recent Signal Types: Scanning, geolocation, subnet analysis, network role classification, ownership verification
## Control Plane Data
- BGP Prefix: 102.251.0.0/19
- Origin ASN: 37457
- Route Changes (30d): 0
- RPKI State: Not available
- IRR Consistency: Not available
- DNSSEC: Valid
## Recommended Actions
The IP presents a moderate risk profile primarily due to DNSBL listings (3 of 8) but lacks confirmed malicious indicators. The following actions are recommended:
1. Monitoring: Continue passive monitoring. No immediate blocking required.
2. DNSBL Review: Investigate the three DNSBL listings to determine relevance. If listings are false positives, consider whitelisting.
3. Traffic Analysis: Monitor for any outbound connections from this IP to known malicious destinations.
4. Residential Context: Given the residential ADSL classification and firewalled service status, treat as legitimate consumer traffic unless threat indicators develop.
## Conclusion
IP 102.251.14.6 is a residential connection in Durban, South Africa, operating under Telkom ADSL infrastructure. No active threat indicators, malicious campaigns, or neighborhood abuse activity detected. The moderate risk score stems primarily from DNSBL listings rather than confirmed malicious behavior. Recommended for continued monitoring rather than immediate action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Chris Aucamp |
| ASN | AS37457 |
| Network Name | 102.251.0.0 - 102.251.255.255 |
| CIDR Block | 102.251.0.0/16 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR | 8ta-251-14-06.telkomadsl.co.za |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 8ta-251-14-06.telkomadsl.co.za |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 06:46:20 UTC |
| Last Seen | 2026-07-29 06:39:51 UTC |
| Profile Built | 2026-07-29 06:52:30 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.