IPDebrief

102.64.34.240

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 102.64.34.240/32

Classification: High Risk (80/100)

Date of Analysis: 2026-07-30

Prepared For: SOC Operations Team

---

## Executive Summary

IP address 102.64.34.240 was classified as High Risk with a risk score of 80/100. The address is geolocated to Vanderbijlpark, Gauteng, South Africa (ZA) and is registered to Jacobus De Beer under ASN 327991. No active services were detected on the IP, though it is assigned a PTR record (ms-34-240.megasurf.co.za) and is listed on 4 out of 8 DNSBLs. No threat indicators (Tor exit, known attacker, spam source) were present in the threat feed data.

---

## Ownership and Network Context

FieldValue
**ASN**327991
**Organization**Jacobus De Beer
**Netname**102.64.34.0 - 102.64.34.255
**CIDR Block**102.64.34.0/24
**RIR**AFRINIC
**Country**South Africa (ZA)
**Region/City**Gauteng / Vanderbijlpark
**Timezone**Africa/Johannesburg

The IP is part of a /24 subnet with 86 total sibling addresses. The neighborhood shows 59 medium-risk and 23 low-risk IPs; no high-risk neighbors were identified. Abuse density for the subnet was recorded at 0.

---

## Technical Profile

---

## Threat Indicators

---

## Historical Observation Summary

15 observations were recorded, most recent at 2026-07-30T22:01:57Z. Historical signals indicate:

---

## Related Entities

---

## Recommended Actions

Immediate Action Required: Increase logging verbosity and review recent activity from this IP.

Firewall Rules:

```

iptables -A INPUT -s 102.64.34.240 -j DROP

nft add rule inet filter input ip saddr 102.64.34.240 drop

nginx: deny 102.64.34.240;

pfSense: 102.64.34.240/32

Cloudflare WAF: Block 102.64.34.240 (risk score 80)

AWS WAF: Block 102.64.34.240/32

```

---

## SOC Analyst Notes

This IP presents an elevated risk profile despite showing no active services or known campaign associations. The high risk score (80/100) combined with DNSBL listings and unstable routing suggests the address should be blocked at the perimeter. Monitor the subnet 102.64.34.0/24 for correlated activity. No immediate threat intelligence (campaigns, known attacker) was present, but the risk score warrants defensive blocking.

Priority: Critical (due to risk score and recommendation severity)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΏπŸ‡¦ South Africa
RegionGauteng
CityVanderbijlpark
TimezoneAfrica/Johannesburg
Latitude-26.71
Longitude27.84

🏒 Ownership & Registration

OrganizationJacobus De Beer
ASNAS327991
Network Name102.64.34.0 - 102.64.34.255
CIDR Block102.64.34.0/24
RIRAFRINIC
CountryZA
Abuse Contactβ€”

🌐 DNS Intelligence

PTRms-34-240.megasurf.co.za
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesms-34-240.megasurf.co.za

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
11
reputation
0%
00
geolocation
0%
00
Overall16%44
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-29 16:40:53 UTC
Last Seen2026-07-31 07:29:39 UTC
Profile Built2026-07-30 22:11:16 UTC
Data FreshnessLive
Signal Types22
Total Observations22
πŸ” 22 signal types Β· 22 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.