IP Intelligence Briefing: 102.64.43.127
Date: June 6, 2026
---
**1. Profile Summary**
- Risk Score: Moderate (40/100)
- Ownership: Registered to Jacobus De Beer (ASN 327991, Megasurf Wireless Internet CC).
- Geolocation: South Africa (ZA), Gauteng, Vanderbijlpark.
- Network Role: Firewalled / No Services (no open ports, no TLS/HTTP activity).
- DNS: Resolves to `ms-43-127.megasurf.co.za` (PTR confirmed).
- Control Plane: BGP prefix `102.64.40.0/21`, DNSSEC valid, no route stability issues.
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- DNS resolution and geolocation data consistent with South Africa.
- No malicious indicators (no blacklists, spam, or known attacker activity).
- Subnet `102.64.43.0/24` has mixed abuse density (0.3056), with 11 high-risk neighbors.
---
**3. Relationships**
- Network: Part of `102.64.43.0/24` (Megasurf, South Africa).
- DNS: Linked to `ms-43-127.megasurf.co.za` (legitimate hostname).
- No direct ties to known malicious campaigns or entities.
---
**4. Neighborhood Analysis**
- Subnet: `102.64.43.0/24` (47 total IPs).
- Abuse Density: 0.191 (19.1% of neighbors flagged as risky).
- High-Risk Neighbors:
- IPs like `102.64.43.9`, `102.64.43.66`, and `102.64.43.235` have risk scores >80.
- Threat Correlation: While the IP itself is clean, the subnet contains risky activity.
---
**5. Recommendations**
- Monitor Subnet: Investigate high-risk neighbors in `102.64.43.0/24` for potential lateral movement or shared infrastructure.
- Verify DNS: Confirm `ms-43-127.megasurf.co.za` is legitimate (e.g., check WHOIS, DNSSEC validity).
- Network Segmentation: Ensure the IP is isolated from sensitive assets, given the subnetβs mixed risk profile.
- Baseline Behavior: Track future activity for anomalies (e.g., unexpected DNS queries, port openings).
---
Conclusion: The IP is associated with a South African ISP and shows no direct malicious activity. However, its subnet contains risky neighbors, warranting further investigation into potential network compromises or shared infrastructure risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Jacobus De Beer |
| ASN | AS327991 |
| Network Name | 102.64.43.0 - 102.64.43.255 |
| CIDR Block | 102.64.43.0/24 |
| RIR | AFRINIC |
| Country | ZA |
| Abuse Contact | β |
π DNS Intelligence
| PTR | ms-43-127.megasurf.co.za |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ms-43-127.megasurf.co.za |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 15% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 02:49:51 UTC |
| Last Seen | 2026-06-26 06:17:41 UTC |
| Profile Built | 2026-06-26 06:22:23 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.