Reporting Potentially Malicious Objects

Reporting Potentially Malicious Objects

Create an exact object list

  1. Open the RADb Query Tool: https://www.radb.net/query

  2. Query the specific objects you want to report

  3. Make sure the objects you are reporting have a “Source: RADb” in their source attribute

    1. If not, please contact the relevant RIR as they are mirrored objects - https://www.irr.net

  4. Save the list in a txt file

Example:

route: 192.122.186.0/24 descr: MERIT Network Inc. 4251 Plymouth Rd Ann Arbor MI 48105-2785, USA origin: AS237 mnt-by: MAINT-AS237 changed: har@merit.edu 20020205 source: RADB route: 192.122.187.0/24 descr: MERIT Network Inc. 4251 Plymouth Rd Ann Arbor MI 48105-2785, USA origin: AS237 mnt-by: MAINT-AS237 changed: har@merit.edu 20020205 source: RADB

Log any maintainer communication

Record any existing communication you have with the maintainer that hosts those objects (dates, channels, and brief outcomes).
If there was no communication, note that clearly.


Explain the impact

  • Briefly explain how these objects might be malicious and how they impact your organizations

  • Please include any relevant data.


Send to RADb Support

Email RADb Support with:

  • The exact object list

  • Communications log

  • How are these objects related to your organization?

  • Any other supporting evidence

RADb Support will investigate and follow up if more details are needed.

Please contact RADb Support for Assistance at support@radb.net or (734) 527-5776.