# IP Intelligence Briefing: 102.33.36.254/32
Classification: High Risk (Score: 80/100)
Date: June 2026
Analyst: IPDebrief SOC Intelligence Team
---
## EXECUTIVE SUMMARY
IP 102.33.36.254 is classified as High Risk (score 80) and is attributed to Metro Fibre Networx (Pty) Ltd (ASN 327782). The IP is geolocated to Pretoria, Gauteng, South Africa. Despite showing a high risk score, the IP presents as firewalled with no open services detected. The address appears on 6 DNS blacklist entries out of 8 total lists monitored, indicating prior abuse or policy violations.
---
## OWNERSHIP & NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **ISP/Provider** | Metro Fibre Networx (Pty) Ltd |
| **Organization** | ORG-MN2-AFRINIC |
| **ASN** | 327782 |
| **CIDR Block** | 102.32.0.0/15 |
| **Country** | South Africa (ZA) |
| **Region** | Gauteng |
| **City** | Pretoria |
| **RIR** | AFRINIC |
---
## THREAT INDICATORS
Blacklist Status: Listed on 6 of 8 monitored DNSBLs
Known Campaigns: None correlated
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Control Plane Data:
- BGP Prefix: 102.33.36.0/23
- Route Stability: Unstable (false)
- Route Changes (30d): 0
- RPKI State: Unknown
- DNSBL Listed: 6/8 lists
---
## NETWORK SERVICES & DNS
- Open Ports: None detected
- Services: Firewalled / No Services
- Reverse DNS (PTR): Not resolved
- Forward DNS: Not confirmed
- Hosted Domains: 0
- TLS Certificate: None
- HTTP Title: None
---
## OBSERVATION HISTORY (22 Signals)
Temporal analysis shows the IP has been observed across multiple signal types since June 17, 2026. Key observations include:
1. Subnet Classification: Clean with 0 abuse density (most recent: June 22, 2026)
2. Operator Score: Minimal (0.2174)
3. Geolocation: Inferred to South Africa (confidence: 0.52)
4. Threat Persistence: 0 days
5. Ownership Changes: 1 recorded
---
## RELATIONSHIP GRAPH (26 Links)
- Network Relationships: 13+ associations to ORG-MN2-AFRINIC (Metro Fibre Networx)
- DNS Associations: Multiple DNS error entries pointing to 192.168.2.108#53 (internal/private IP)
- No External Hostname Associations
---
## SUBNET ANALYSIS (102.33.36.0/24)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Abuse Density: 0
- Inherited Risk: 0
- Classification: Clean
---
## RECOMMENDED ACTIONS
Based on the high-risk classification and DNSBL listings:
1. Rate Limiting: Apply connection rate limiting to the IP at the perimeter firewall
2. DNSBL Monitoring: Continue monitoring blacklist status
3. Traffic Analysis: Inspect traffic patterns for potential spoofing or proxy use
4. Block Decision: Monitor for sustained malicious activity before implementing permanent blocking
---
## CONCLUSION
IP 102.33.36.254 presents a high-risk profile primarily due to DNS blacklist associations and control plane instability. However, the absence of open services and clean neighborhood data suggests this may be a passive or previously compromised endpoint. SOC teams should monitor for activity patterns and apply defensive controls while maintaining situational awareness.
Status: Active Monitoring Recommended
Priority: Medium (High Risk Score, No Active Services)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Metro Fibre Networx (Pty) Ltd |
| ASN | AS327782 |
| Network Name | ORG-MN2-AFRINIC |
| CIDR Block | 102.32.0.0/15 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 22% | 3 | 3 |
| services | 26% | 2 | 3 |
| ownership | 24% | 2 | 2 |
| reputation | 21% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 12 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Fresh
| First Seen | 2026-05-07 23:03:24 UTC |
| Last Seen | 2026-06-26 18:10:11 UTC |
| Profile Built | 2026-06-25 02:59:54 UTC |
| Data Freshness | Fresh |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.