# IP INTELLIGENCE BRIEFING
Target: 102.64.34.215/32
Date: 2026-07-30
Classification: Moderate Risk
---
## EXECUTIVE SUMMARY
IP 102.64.34.215 is a moderate-risk address (Risk Score: 55/100) registered to Jacobus De Beer under ASN 327991. The IP is geolocated to Vanderbijlpark, Gauteng, South Africa (ZA) and resolves to hostname ms-34-215.megasurf.co.za. No active services or open ports were detected, indicating the host is likely firewalled or inactive. The IP is listed on 3 of 8 DNSBL entries, suggesting prior abuse activity.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **ASN** | 327991 |
| **Organization** | Jacobus De Beer |
| **Netname** | 102.64.34.0 - 102.64.34.255 |
| **RIR** | AFRINIC |
| **CIDR Block** | 102.64.34.0/24 |
| **Geolocation** | Vanderbijlpark, Gauteng, South Africa |
| **DNS Resolves** | ms-34-215.megasurf.co.za |
| **PTR Record** | ms-34-215.megasurf.co.za |
---
## THREAT ASSESSMENT
Risk Score: 55/100 (Moderate Risk)
Reputation: Moderate Risk
Threat Indicators:
- DNSBL Listed: 3/8 lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Services: None detected (firewalled/no services)
- Known Campaigns: None identified
Control Plane:
- Route Stability: Unstable (isRouteStable: false)
- BGP Prefix: 102.64.32.0/21
- DNSSEC Valid: Yes
- Operator Score: 0.2609 (Basic)
---
## OBSERVATION HISTORY
Analysis of 15 signal observations reveals:
- Recent Classification: mostly_clean
- Abuse Density: 0.0698 (low)
- Inherited Risk: 2 (minimal)
- Subnet Siblings: 86 total, 42 active, 6 with threat indicators
Geolocation signals consistently identify the IP as South African with coordinates (-26.7005, 27.8179) and 800km accuracy radius. ICMP validation blocked due to network configuration.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 102.64.34.0/24
Total Neighbors: 85
Risk Distribution:
- High Risk: 0
- Medium Risk: 58
- Low Risk: 23
Notable Neighboring IPs:
- 102.64.34.29: Risk Score 55 (matches target)
- 102.64.34.9: Risk Score 30
- 102.64.34.30: Risk Score 40
The subnet exhibits moderate risk concentration with 58/85 neighbors flagged as medium risk. Abuse density remains at 0.
---
## RELATIONSHIP MAPPING
Eight relationship indicators identified:
- Same Network: 102.64.34.0 - 102.64.34.255 (multiple associations)
- DNS Associations: ms-34-215.megasurf.co.za (multiple records)
No external organization or certificate relationships detected beyond immediate subnet and DNS associations.
---
## RECOMMENDED ACTIONS
Priority: Monitor/Review
Severity: High (based on risk score elevation)
Recommended Actions:
1. Increase logging verbosity for traffic from this IP and review recent activity patterns
2. Implement firewall blocks if traffic is confirmed malicious
3. Monitor neighboring IPs in 102.64.34.0/24 subnet for coordinated activity
Firewall Rules:
- iptables: `iptables -A INPUT -s 102.64.34.215 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 102.64.34.215 drop`
- nginx: `deny 102.64.34.215;`
- pfSense: `102.64.34.215/32`
- Cloudflare WAF: Block IP with expression `ip.src eq 102.64.34.215`
- AWS WAF: Add `102.64.34.215/32` to IP set
---
## CONCLUSION
IP 102.64.34.215 presents moderate risk with elevated DNSBL listings but no confirmed active malicious services. The subnet environment shows 58/85 neighbors at medium risk, warranting contextual monitoring. Recommend increased logging and activity review; consider blocking if traffic correlates with known malicious behavior. The absence of open ports and active services suggests the IP is either dormant or heavily firewalled.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Jacobus De Beer |
| ASN | AS327991 |
| Network Name | 102.64.34.0 - 102.64.34.255 |
| CIDR Block | 102.64.34.0/24 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ms-34-215.megasurf.co.za |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ms-34-215.megasurf.co.za |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | High (85%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 10:05:51 UTC |
| Last Seen | 2026-08-11 17:57:34 UTC |
| Profile Built | 2026-08-11 11:49:49 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.