IPDebrief

102.64.34.215

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 102.64.34.215/32

Date: 2026-07-30

Classification: Moderate Risk

---

## EXECUTIVE SUMMARY

IP 102.64.34.215 is a moderate-risk address (Risk Score: 55/100) registered to Jacobus De Beer under ASN 327991. The IP is geolocated to Vanderbijlpark, Gauteng, South Africa (ZA) and resolves to hostname ms-34-215.megasurf.co.za. No active services or open ports were detected, indicating the host is likely firewalled or inactive. The IP is listed on 3 of 8 DNSBL entries, suggesting prior abuse activity.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**ASN**327991
**Organization**Jacobus De Beer
**Netname**102.64.34.0 - 102.64.34.255
**RIR**AFRINIC
**CIDR Block**102.64.34.0/24
**Geolocation**Vanderbijlpark, Gauteng, South Africa
**DNS Resolves**ms-34-215.megasurf.co.za
**PTR Record**ms-34-215.megasurf.co.za

---

## THREAT ASSESSMENT

Risk Score: 55/100 (Moderate Risk)

Reputation: Moderate Risk

Threat Indicators:

Control Plane:

---

## OBSERVATION HISTORY

Analysis of 15 signal observations reveals:

Geolocation signals consistently identify the IP as South African with coordinates (-26.7005, 27.8179) and 800km accuracy radius. ICMP validation blocked due to network configuration.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 102.64.34.0/24

Total Neighbors: 85

Risk Distribution:

Notable Neighboring IPs:

The subnet exhibits moderate risk concentration with 58/85 neighbors flagged as medium risk. Abuse density remains at 0.

---

## RELATIONSHIP MAPPING

Eight relationship indicators identified:

No external organization or certificate relationships detected beyond immediate subnet and DNS associations.

---

## RECOMMENDED ACTIONS

Priority: Monitor/Review

Severity: High (based on risk score elevation)

Recommended Actions:

1. Increase logging verbosity for traffic from this IP and review recent activity patterns

2. Implement firewall blocks if traffic is confirmed malicious

3. Monitor neighboring IPs in 102.64.34.0/24 subnet for coordinated activity

Firewall Rules:

---

## CONCLUSION

IP 102.64.34.215 presents moderate risk with elevated DNSBL listings but no confirmed active malicious services. The subnet environment shows 58/85 neighbors at medium risk, warranting contextual monitoring. Recommend increased logging and activity review; consider blocking if traffic correlates with known malicious behavior. The absence of open ports and active services suggests the IP is either dormant or heavily firewalled.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΏπŸ‡¦ South Africa
RegionGauteng
CityVanderbijlpark
TimezoneAfrica/Johannesburg
Latitude-26.70
Longitude27.82

🏒 Ownership & Registration

OrganizationJacobus De Beer
ASNAS327991
Network Name102.64.34.0 - 102.64.34.255
CIDR Block102.64.34.0/24
RIRAFRINIC
CountryZA
Abuse Contactβ€”

🌐 DNS Intelligence

PTRms-34-215.megasurf.co.za
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesms-34-215.megasurf.co.za

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
11
reputation
0%
00
geolocation
0%
00
Overall16%44
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionHigh (85%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-28 10:05:51 UTC
Last Seen2026-08-11 17:57:34 UTC
Profile Built2026-08-11 11:49:49 UTC
Data FreshnessLive
Signal Types24
Total Observations25
πŸ” 24 signal types Β· 25 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.