[afnog] Africacert opinion on cybersecurity threat Intelligence

Loganaden Velvindron loganaden at gmail.com
Mon Sep 28 18:05:34 UTC 2026


I forgot to cc Ben who represents AFRINIC.




On Mon, 28 Sept 2026, 21:38 Loganaden Velvindron, <loganaden at gmail.com>
wrote:

>
>
> On Mon, 28 Sept 2026, 17:20 , <sm+afrinic at elandsys.com> wrote:
>
>> Hi Logan,
>> At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:
>> >Yes. This can be used as data feed to update IP blocklists which are
>> >maintained by Cybersecurity
>> >Threat Intel companies.
>>
>> I apologize for getting back to the above.
>>
>> An unallocated /13 was found to be in use last March [1].  I didn't
>> notice the incident as there wasn't any email about it (it's not in
>> the mailing list archives for that period).  There would be network
>> ranges within the /13 in blocklists if there was any problematic
>> traffic originating from them.
>>
>
> "102.224.0.0/13, "reserved [by AFRINIC] for future as per section 5.4.7.1
> of [AFRINIC's] consolidated policy manual Version 1.1", according to its
> AFRINIC."
>
>
> According to spamhaus, this IP block is managed by AFRINIC.
>
> @ben:
> Does afrinic have a documented process for those operational incidents ?
>
>
>
>> I'll comment on problematic traffic.  There was the following request
>> a few minutes ago:
>>
>>    "POST /wordpress/wordpress/wp-json/batch/v1 HTTP/1.1"
>>
>> from 45.148.10.40.  The remote device could be targeting this
>> vulnerability:
>>
>> https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
>> I would be spending time on non-security events if I were to list the
>> vulnerability as a potential threat.
>>
>
> I am also noticing spikes of 4 million connections in a single day from 4
> IP addresses.
>
>>
>> There was three connection attempts to SSH which were similar to:
>>
>>    Invalid user  from 2001:470:1:c84::28 port 4424
>>
>> For what it is worth, a remote device was running a scan.  Those
>> connections would not cause any adverse effect.  What if the remote
>> device in either of the two cases was connecting from within the
>> /13?  It would get listed somewhere.  Data in the list is packaged in
>> other lists and sold as data feeds.  What the user will see is a
>> notice in his/her browser about being blocked and the IP address from
>> which he/she connected.  An IT expert
>
>
> Is this why i am often hitting captcha from certain IP address blocks in
> the african region ?
>
>
> will advise the user to get
>> another service provider as the current service provider was not
>> interested in fixing the problem.
>>
>
> Is abuse contact still considered a sufficient mechanism in 2026 ?
>
> What is your opinion about whowas ?
>
>
>
>
>> Regards,
>> S. Moonesamy
>>
>> 1. https://www.elandsys.com/r/82740
>>
>>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.afnog.org/pipermail/afnog/attachments/20260928/2e15219b/attachment.html>


More information about the afnog mailing list