IOC Radar
IPMediumSignal 60/100

102.64.36.187

Location
South AfricaSouth Africa
Vanderbijlpark, GP
ASN
AS327991
Megasurf Wireless Internet CC
First Seen
Oct 27, 2025
Last Seen
Jun 2, 2026
Oct 27
First Seen
228d ago
Jun 2
Last Seen
10d ago
10
Reports
source reports
60%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
60%
Signal Score
60 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

7 techniques

Network Information

CountryZASouth Africa
RegionVanderbijlpark, GP
ASNAS327991
OrganizationMegasurf Wireless Internet CC

Feed Intelligence Summary

10 reports60% confidence
10
Source reports
60%
Confidence score
Category tags
abuseactive scanactive scanningafricaaptbad reputationbrute forcebrute force attackbrute-forcecredential accesscredential stuffingddosddos attackexploitation activityidentity & access exploitationimapimap attackindicatornetworkpassword attacksreconnaissanceresearchedscannersmtpsmtp attackersouth africassh attackt1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003threat actortor node

Activity Timeline

1 total obs
Jun 2Jun 2

Threat Activity Heatmap

· Peak: 2026-06-02
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
60
SIGNAL
Signal Score
60%
Confidence
10
Reports
First seenOct 27, 2025
Last seenJun 2, 2026
GeolocationZA
CountrySouth Africa
LocationVanderbijlpark, GP
ASNAS327991
OrgMegasurf Wireless Internet CC
Coords-26.7005, 27.8179

VirusTotal

Not checked

WHOIS

description
The following is the full list of names given to Vye32GsS2g38eKhmaKrLdDjgrnf2YBT4/FGx8SNCa4txePA
raw
inetnum: 102.64.36.0 - 102.64.36.255 netname: Megasurf-Wireless descr: Use for wireless and FTTH clients PPPOE assignment country: ZA admin-c: JM85-AFRINIC tech-c: JDB1-AFRINIC tech-c: JM85-AFRINIC status: ASSIGNED PA mnt-by: MEGASURF-WIRELESS-MNT source: AFRINIC # Filtered parent: 102.64.32.0 - 102.64.47.255 person: Jacobus De Beer nic-hdl: JDB1-AFRINIC address: 149 Louis Trichardt street address: Vanderbijlpark 1911 address: South Africa phone: tel:+27-61-549-2946 mnt-by: GENERATED-YLMR5NTHXKCBXE5VHQWYBURLCW8Q24EJ-MNT source: AFRINIC # Filtered person: Jackson Marius address: 149 Louis Trichardt street address: Vanderbijlapark 1911 address: South Africa phone: tel:+27-82-822-4724 nic-hdl: JM85-AFRINIC mnt-by: GENERATED-CIOEUBSDJDPSJPUUWZSI4UXI2ID3W50G-MNT source: AFRINIC # Filtered route: 102.64.32.0/21 descr: Megasurf Wireless Internet CC origin: AS327991 mnt-by: MEGASURF-WIRELESS-MNT source: AFRINIC # Filtered org: ORG-MWIC1-AFRINIC organisation: ORG-MWIC1-AFRINIC org-name: Megasurf Wireless Internet CC org-type: LIR country: ZA address: 149 Louis Trichardt street address: Vanderbijlpark 1911 phone: tel:+27-16-932-2324 phone: tel:+27-16-932-2324 phone: tel:+27-16-932-2324 fax-no: tel:+27-86-657-5980 admin-c: CE44-AFRINIC admin-c: JM85-AFRINIC tech-c: HO15-AFRINIC tech-c: JM85-AFRINIC tech-c: TG31-AFRINIC mnt-ref: AFRINIC-HM-MNT mnt-ref: MEGASURF-WIRELESS-MNT mnt-by: AFRINIC-HM-MNT source: AFRINIC # Filtered
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 7 months ago · Last seen 10 days ago
Appeared in 10 threat reports