[afnog] Africacert opinion on cybersecurity threat Intelligence

Loganaden Velvindron loganaden at gmail.com
Mon Sep 28 17:38:29 UTC 2026


On Mon, 28 Sept 2026, 17:20 , <sm+afrinic at elandsys.com> wrote:

> Hi Logan,
> At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:
> >Yes. This can be used as data feed to update IP blocklists which are
> >maintained by Cybersecurity
> >Threat Intel companies.
>
> I apologize for getting back to the above.
>
> An unallocated /13 was found to be in use last March [1].  I didn't
> notice the incident as there wasn't any email about it (it's not in
> the mailing list archives for that period).  There would be network
> ranges within the /13 in blocklists if there was any problematic
> traffic originating from them.
>

"102.224.0.0/13, "reserved [by AFRINIC] for future as per section 5.4.7.1
of [AFRINIC's] consolidated policy manual Version 1.1", according to its
AFRINIC."


According to spamhaus, this IP block is managed by AFRINIC.

@ben:
Does afrinic have a documented process for those operational incidents ?



> I'll comment on problematic traffic.  There was the following request
> a few minutes ago:
>
>    "POST /wordpress/wordpress/wp-json/batch/v1 HTTP/1.1"
>
> from 45.148.10.40.  The remote device could be targeting this
> vulnerability:
>
> https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
> I would be spending time on non-security events if I were to list the
> vulnerability as a potential threat.
>

I am also noticing spikes of 4 million connections in a single day from 4
IP addresses.

>
> There was three connection attempts to SSH which were similar to:
>
>    Invalid user  from 2001:470:1:c84::28 port 4424
>
> For what it is worth, a remote device was running a scan.  Those
> connections would not cause any adverse effect.  What if the remote
> device in either of the two cases was connecting from within the
> /13?  It would get listed somewhere.  Data in the list is packaged in
> other lists and sold as data feeds.  What the user will see is a
> notice in his/her browser about being blocked and the IP address from
> which he/she connected.  An IT expert


Is this why i am often hitting captcha from certain IP address blocks in
the african region ?


will advise the user to get
> another service provider as the current service provider was not
> interested in fixing the problem.
>

Is abuse contact still considered a sufficient mechanism in 2026 ?

What is your opinion about whowas ?




> Regards,
> S. Moonesamy
>
> 1. https://www.elandsys.com/r/82740
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.afnog.org/pipermail/afnog/attachments/20260928/323a82ee/attachment.html>


More information about the afnog mailing list