[afnog] Africacert opinion on cybersecurity threat Intelligence
Loganaden Velvindron
loganaden at gmail.com
Mon Sep 28 17:38:29 UTC 2026
On Mon, 28 Sept 2026, 17:20 , <sm+afrinic at elandsys.com> wrote:
> Hi Logan,
> At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:
> >Yes. This can be used as data feed to update IP blocklists which are
> >maintained by Cybersecurity
> >Threat Intel companies.
>
> I apologize for getting back to the above.
>
> An unallocated /13 was found to be in use last March [1]. I didn't
> notice the incident as there wasn't any email about it (it's not in
> the mailing list archives for that period). There would be network
> ranges within the /13 in blocklists if there was any problematic
> traffic originating from them.
>
"102.224.0.0/13, "reserved [by AFRINIC] for future as per section 5.4.7.1
of [AFRINIC's] consolidated policy manual Version 1.1", according to its
AFRINIC."
According to spamhaus, this IP block is managed by AFRINIC.
@ben:
Does afrinic have a documented process for those operational incidents ?
> I'll comment on problematic traffic. There was the following request
> a few minutes ago:
>
> "POST /wordpress/wordpress/wp-json/batch/v1 HTTP/1.1"
>
> from 45.148.10.40. The remote device could be targeting this
> vulnerability:
>
> https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
> I would be spending time on non-security events if I were to list the
> vulnerability as a potential threat.
>
I am also noticing spikes of 4 million connections in a single day from 4
IP addresses.
>
> There was three connection attempts to SSH which were similar to:
>
> Invalid user from 2001:470:1:c84::28 port 4424
>
> For what it is worth, a remote device was running a scan. Those
> connections would not cause any adverse effect. What if the remote
> device in either of the two cases was connecting from within the
> /13? It would get listed somewhere. Data in the list is packaged in
> other lists and sold as data feeds. What the user will see is a
> notice in his/her browser about being blocked and the IP address from
> which he/she connected. An IT expert
Is this why i am often hitting captcha from certain IP address blocks in
the african region ?
will advise the user to get
> another service provider as the current service provider was not
> interested in fixing the problem.
>
Is abuse contact still considered a sufficient mechanism in 2026 ?
What is your opinion about whowas ?
> Regards,
> S. Moonesamy
>
> 1. https://www.elandsys.com/r/82740
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.afnog.org/pipermail/afnog/attachments/20260928/323a82ee/attachment.html>
More information about the afnog
mailing list