# IP Intelligence Briefing: 102.64.34.240/32
Classification: High Risk (80/100)
Date of Analysis: 2026-07-30
Prepared For: SOC Operations Team
---
## Executive Summary
IP address 102.64.34.240 was classified as High Risk with a risk score of 80/100. The address is geolocated to Vanderbijlpark, Gauteng, South Africa (ZA) and is registered to Jacobus De Beer under ASN 327991. No active services were detected on the IP, though it is assigned a PTR record (ms-34-240.megasurf.co.za) and is listed on 4 out of 8 DNSBLs. No threat indicators (Tor exit, known attacker, spam source) were present in the threat feed data.
---
## Ownership and Network Context
| Field | Value |
|---|---|
| **ASN** | 327991 |
| **Organization** | Jacobus De Beer |
| **Netname** | 102.64.34.0 - 102.64.34.255 |
| **CIDR Block** | 102.64.34.0/24 |
| **RIR** | AFRINIC |
| **Country** | South Africa (ZA) |
| **Region/City** | Gauteng / Vanderbijlpark |
| **Timezone** | Africa/Johannesburg |
The IP is part of a /24 subnet with 86 total sibling addresses. The neighborhood shows 59 medium-risk and 23 low-risk IPs; no high-risk neighbors were identified. Abuse density for the subnet was recorded at 0.
---
## Technical Profile
- Service Status: Firewalled / No Services (no open ports detected)
- DNS PTR: ms-34-240.megasurf.co.za (forward confirmed)
- Email Authentication: SPF record present
- DNSSEC: Valid
- BGP Prefix: 102.64.32.0/21
- Route Stability: Unstable
- Operator Score: 0.2609 (Basic)
- Geographic Validation: Not plausible (geoPlausible: false)
- Traceroute: 30 hops, 12 timed out, transit includes Comcast
---
## Threat Indicators
- Risk Score: 80/100 (High Risk)
- Blacklist Count: 0
- DNSBL Listed: 4 of 8 lists
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Known Campaigns: None identified
- Threat Persistence Days: 0
- Persistently Malicious: No
---
## Historical Observation Summary
15 observations were recorded, most recent at 2026-07-30T22:01:57Z. Historical signals indicate:
- Geolocation inferences to South Africa
- Operator classification as "Basic"
- Network classification as residential/infrastructure
- No ownership changes detected
---
## Related Entities
- Hostname: ms-34-240.megasurf.co.za
- Network: 102.64.34.0/24
- Associated Organization: Jacobus De Beer
---
## Recommended Actions
Immediate Action Required: Increase logging verbosity and review recent activity from this IP.
Firewall Rules:
```
iptables -A INPUT -s 102.64.34.240 -j DROP
nft add rule inet filter input ip saddr 102.64.34.240 drop
nginx: deny 102.64.34.240;
pfSense: 102.64.34.240/32
Cloudflare WAF: Block 102.64.34.240 (risk score 80)
AWS WAF: Block 102.64.34.240/32
```
---
## SOC Analyst Notes
This IP presents an elevated risk profile despite showing no active services or known campaign associations. The high risk score (80/100) combined with DNSBL listings and unstable routing suggests the address should be blocked at the perimeter. Monitor the subnet 102.64.34.0/24 for correlated activity. No immediate threat intelligence (campaigns, known attacker) was present, but the risk score warrants defensive blocking.
Priority: Critical (due to risk score and recommendation severity)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Jacobus De Beer |
| ASN | AS327991 |
| Network Name | 102.64.34.0 - 102.64.34.255 |
| CIDR Block | 102.64.34.0/24 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ms-34-240.megasurf.co.za |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ms-34-240.megasurf.co.za |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 16:40:53 UTC |
| Last Seen | 2026-07-31 07:29:39 UTC |
| Profile Built | 2026-07-30 22:11:16 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.