IP Intelligence Briefing: 102.64.37.207
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: 55/100 (Moderate Risk)
- Ownership: Registered to Jacobus De Beer (ASN 327991) under Megasurf Wireless Internet CC (South Africa).
- Geolocation: Vanderbijlpark, Gauteng, South Africa (latitude -26.7, longitude 27.82).
- Network Role: Unknown infrastructure; no active services or cloud/CDN indicators.
- Threat Indicators: No malicious activity detected (no malware, phishing, or C2 indicators).
---
**2. Observation History (30-Day Window)**
- Geolocation: Confirmed via multi-signal inference (confidence: 52%).
- BGP Prefix: Associated with 102.64.32.0/21 (Megasurf Wireless).
- DNS: Resolves to ms-37-207.megasurf.co.za with SPF/DMArc validation.
- Subnet Abuse Density: 0.27 (low, but 13/48 neighbors flagged as high/medium risk).
---
**3. Relationships & Network Context**
- DNS Associations: Linked to ms-37-207.megasurf.co.za (4 instances).
- Subnet: Part of 102.64.37.0/24 with 48 total IPs (8 active, 13 flagged as risky).
- Routing: DNSSEC valid, no CAA records.
- Neighbor Risks: 6 high-risk neighbors (e.g., 102.64.37.42, 102.64.37.58).
---
**4. Actionable Recommendations**
- Monitoring: Increase logging verbosity for traffic from this IP due to moderate risk.
- Firewall Rules:
- iptables: `iptables -A INPUT -s 102.64.37.207 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 102.64.37.207 drop`
- Cloudflare/WAF: Block IP with rule: `ip.src eq 102.64.37.207`
- Network Review: Investigate high-risk neighbors in the 102.64.37.0/24 subnet.
---
**5. Summary**
The IP is registered to a South African ISP and shows no direct malicious activity. However, its subnet contains high-risk neighbors, and the moderate risk score suggests closer monitoring. Ensure DNS and email security configurations are robust, and consider blocking this IP to mitigate potential lateral movement risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Jacobus De Beer |
| ASN | AS327991 |
| Network Name | 102.64.37.0 - 102.64.37.255 |
| CIDR Block | 102.64.37.0/24 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ms-37-207.megasurf.co.za |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ms-37-207.megasurf.co.za |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 24% | 2 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 13% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 09:35:56 UTC |
| Last Seen | 2026-06-08 18:30:08 UTC |
| Profile Built | 2026-06-08 18:34:48 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 19 |
Full dossier details are available via our API.