## IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 102.64.33.189/32
Report Generated: 2026-07-30
Classification: Moderate Risk
---
EXECUTIVE SUMMARY
IP 102.64.33.189 presents a moderate risk profile (55/100) originating from South Africa. The address is associated with Jacobus De Beer (ASN 327991) within the 102.64.33.0/24 block. No open services are detected on the target, but the IP shows 3 DNSBL listings and has been observed with elevated risk indicators. The subnet exhibits 15% abuse density with 15 threat-sibling IPs among 100 total addresses.
---
OWNERSHIP & GEOLLOCATION
| Attribute | Value |
|---|---|
| **Organization** | Jacobus De Beer |
| **ASN** | 327991 |
| **Network Block** | 102.64.33.0/24 |
| **Country** | South Africa (ZA) |
| **Region** | Gauteng |
| **City** | Vanderbijlpark |
| **Timezone** | Africa/Johannesburg |
| **RIR** | AFRINIC |
| **PTR Hostname** | ms-33-189.megasurf.co.za |
---
THREAT ASSESSMENT
Current Risk Score: 55/100 (Moderate Risk)
Threat Indicators:
- Blacklist Status: Listed on 3 of 8 DNSBL feeds
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Persistently Malicious: No
- Threat Observation Count: 1
- Campaign Correlation: None detected
Network Classification:
- Infrastructure Type: Residential/Hosting (firewalled)
- Open Ports: None detected
- Service Purpose: Firewalled / No Services
- Connection Type: Not cloud, CDN, VPN, proxy, or mobile
---
NEIGHBORHOOD ANALYSIS
Subnet: 102.64.33.0/24
Abuse Density: 0.15 (15%)
Classification: mostly_clean
Risk Distribution (99 sibling IPs):
- High Risk: 1 IP
- Medium Risk: 71 IPs
- Low Risk: 21 IPs
Notable Siblings:
- 102.64.33.1 (Risk: 40, Authority: 60)
- 102.64.33.2 (Risk: 30, Authority: 60)
- 102.64.33.9 (Risk: 15, Authority: 60)
- 102.64.33.12 (Risk: 40, Authority: 60)
---
OBSERVATION HISTORY
Total Signals: 18 observations
Recent Activity (2026-07-30):
- Traceroute observation (30 hops, target not reached)
- Subnet abuse density classification: mostly_clean
- Ownership stability: No changes
- Geographic inference: Vanderbijlpark, ZA (52% confidence)
- DNSBL listings detected (3 of 8 total)
Temporal Indicators:
- Threat Persistence Days: 0
- Ownership Changes: 0
- Is Persistently Malicious: No
---
NETWORK RELATIONSHIPS
Primary Associations:
- DNS: ms-33-189.megasurf.co.za
- Network: 102.64.33.0 - 102.64.33.255 (multiple relationships)
---
RECOMMENDED ACTIONS
Monitoring:
- Increase logging verbosity and review recent activity from this IP
- Severity: High (based on risk score 55/100)
Firewall Rules:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 102.64.33.189 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 102.64.33.189 drop` |
| nginx | `deny 102.64.33.189;` |
| pfSense | `102.64.33.189/32` |
| Cloudflare WAF | Block IP (risk score 55) |
| AWS WAF | Block 102.64.33.189/32 |
---
ANALYST NOTES
This IP represents a moderate-risk address with no active open services. The subnet shows elevated abuse density (15%) with 15 threat-sibling IPs. While the target itself is firewalled, the neighborhood context suggests potential for abuse from related addresses. Recommended approach: implement monitoring with logging enhancement, consider blocking if traffic patterns indicate malicious intent. No immediate threat indicators (no campaigns, no known attacker status, no persistent malice) warrant emergency response.
Confidence Level: Moderate β based on DNSBL listings and risk score, but lacking active exploit signatures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Jacobus De Beer |
| ASN | AS327991 |
| Network Name | 102.64.33.0 - 102.64.33.255 |
| CIDR Block | 102.64.33.0/24 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ms-33-189.megasurf.co.za |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ms-33-189.megasurf.co.za |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 1 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 14:52:11 UTC |
| Last Seen | 2026-08-13 12:52:03 UTC |
| Profile Built | 2026-07-30 03:56:09 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.