<div dir="auto"><div>I forgot to cc Ben who represents AFRINIC.<div dir="auto"><br></div><div dir="auto"><br></div><br><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Mon, 28 Sept 2026, 21:38 Loganaden Velvindron, <<a href="mailto:loganaden@gmail.com">loganaden@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="auto"><div><br><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, 28 Sept 2026, 17:20 , <<a href="mailto:sm%2Bafrinic@elandsys.com" rel="noreferrer noreferrer" target="_blank">sm+afrinic@elandsys.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Logan,<br>
At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:<br>
>Yes. This can be used as data feed to update IP blocklists which are<br>
>maintained by Cybersecurity<br>
>Threat Intel companies.<br>
<br>
I apologize for getting back to the above.<br>
<br>
An unallocated /13 was found to be in use last March [1]. I didn't <br>
notice the incident as there wasn't any email about it (it's not in <br>
the mailing list archives for that period). There would be network <br>
ranges within the /13 in blocklists if there was any problematic <br>
traffic originating from them.<br></blockquote></div></div><div dir="auto"><br></div><div dir="auto">"<a href="http://102.224.0.0/13" target="_blank" rel="noreferrer">102.224.0.0/13</a>, "reserved [by AFRINIC] for future as per section 5.4.7.1 of [AFRINIC's] consolidated policy manual Version 1.1", according to its AFRINIC."</div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto">According to spamhaus, this IP block is managed by AFRINIC.</div><div dir="auto"><br></div><div dir="auto">@ben:</div><div dir="auto">Does afrinic have a documented process for those operational incidents ?</div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
I'll comment on problematic traffic. There was the following request <br>
a few minutes ago:<br>
<br>
"POST /wordpress/wordpress/wp-json/batch/v1 HTTP/1.1"<br>
<br>
from 45.148.10.40. The remote device could be targeting this <br>
vulnerability: <br>
<a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf</a> <br>
I would be spending time on non-security events if I were to list the <br>
vulnerability as a potential threat.<br></blockquote></div></div><div dir="auto"><br></div><div dir="auto">I am also noticing spikes of 4 million connections in a single day from 4 IP addresses.</div><div dir="auto"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
There was three connection attempts to SSH which were similar to:<br>
<br>
Invalid user from 2001:470:1:c84::28 port 4424<br>
<br>
For what it is worth, a remote device was running a scan. Those <br>
connections would not cause any adverse effect. What if the remote <br>
device in either of the two cases was connecting from within the <br>
/13? It would get listed somewhere. Data in the list is packaged in <br>
other lists and sold as data feeds. What the user will see is a <br>
notice in his/her browser about being blocked and the IP address from <br>
which he/she connected. An IT expert</blockquote></div></div><div dir="auto"><br></div><div dir="auto"></div><div dir="auto">Is this why i am often hitting captcha from certain IP address blocks in the african region ?</div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> will advise the user to get <br>
another service provider as the current service provider was not <br>
interested in fixing the problem.<br></blockquote></div></div><div dir="auto"><br></div><div dir="auto">Is abuse contact still considered a sufficient mechanism in 2026 ?</div><div dir="auto"><br></div><div dir="auto">What is your opinion about whowas ?</div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
Regards,<br>
S. Moonesamy<br>
<br>
1. <a href="https://www.elandsys.com/r/82740" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">https://www.elandsys.com/r/82740</a> <br>
<br>
</blockquote></div></div></div>
</blockquote></div></div></div>