NANOG mailing list participants sought an accurate list of IP ranges tied to Cloud Innovation after operators reported attack traffic from Seychelles-associated networks that were now receiving transit through Cox Communications (AS22773). David Hubbard said the routing change complicated mitigation because blocking Cox would also affect substantial legitimate traffic, turning what had been a more targeted filtering problem into a broader operational risk.
The discussion also highlighted that many of the same networks appeared to be routed by AS35916 (identified in the thread as Multacom), with more specific advertisements seen via Cox, raising questions about whether Cloud Innovation and Multacom are the same entity or have a business relationship. In reply, Frank Habicht shared AFRINIC delegation data associated with identifier F368F2D0 and provided four large IPv4 CIDR blocks, while cautioning that any use of the list for blocking should be done at the operator's own risk.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
In response to the NANOG discussion, Frank Habicht shared AFRINIC delegation data tied to identifier F368F2D0 and listed four large IPv4 CIDR blocks he said were associated with Cloud Innovation, noting they should be used at one's own risk. This added concrete network ranges to the ongoing operational discussion about filtering attack traffic.
David Hubbard posted to the NANOG mailing list that some Seychelles-associated networks he considered questionable were receiving transit through Cox Communications' AS22773, complicating mitigation because blocking Cox would also affect legitimate traffic. He also said many of the same networks appeared to be routed by AS35916 (identified as Multacom), raising questions about the relationship between Cloud Innovation and Multacom.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.