Malicious IPs in South Africa

IPv4 networks located in South Africa that are currently flagged for malicious activity, aggregated from multiple external and internal threat intelligence sources. Snapshot of (UTC), updated daily.

Flagged IPv4 networks
131
#28 of 179 countries
Per million allocated IPv4
4.82
#56 of 76 countries
Flagged IPv4 addresses
933
ranges count at most as a /24
Allocated IPv4 addresses
27,184,896
RIR delegation statistics

South Africa at a glance

South Africa had 131 flagged IPv4 networks in the snapshot of 2026-10-11, rank #28 of 179 countries by absolute count. Relative to its allocated IPv4 space that is 4.82 flagged networks per million addresses, rank #56 of 76, well below the median of 9.38 across all rated countries. The largest category is brute force sources with 65% of the flagged networks, followed by other malicious networks (19%). The three networks (ASNs) with the most flagged IPs hold 36% of them, led by MEGASURF-WIRELESS-INTERNET (AS327991). Another 2 flagged IPv6 networks are located in South Africa.

Malicious activity in South Africa by category

A network listed in several categories counts once, in the most specific one. Also flagged: 2 IPv6 networks.

  • Brute force sources in South Africa

    85 (65%)

    85 flagged networks, #25 of 162 countries for brute force sources. Sources of password guessing against SSH, mail, FTP and web logins. Brute Force Sources by Country

  • Other malicious networks in South Africa

    25 (19%)

    25 flagged networks, #28 of 143 countries for other malicious networks. Addresses and ranges reported as malicious without a more specific category. Other Malicious Networks by Country

  • Botnet hosts in South Africa

    15 (11%)

    15 flagged networks, #21 of 122 countries for botnet hosts. Infected hosts taking part in a botnet. Botnet Hosts by Country

  • Spam sources in South Africa

    5 (4%)

    5 flagged networks, #26 of 89 countries for spam sources. Sources of email spam. Spam Sources by Country

  • C2 servers in South Africa

    1 (1%)

    1 flagged network, #34 of 51 countries for C2 servers. Command-and-control servers, payload hosts and other attacker-run infrastructure. C2 Servers by Country

Networks with the most flagged IPs in South Africa

Autonomous systems announcing the flagged networks located in South Africa.

#NetworkFlagged networks
1AS327991MEGASURF-WIRELESS-INTERNET28
2AS37611AFRIHOST-SP10
3AS20011NTT-DATA-Inc9
4AS37457Telkom-Internet9
5AS36994Vodacom-VB8
6AS328471Hero-Telecoms4
7AS37049SADV4
8AS12091MTNNS-14
9AS37105RAIN-GROUP-HOLDINGS4
10AS327782METROFIBRE-NETWORX4

Compare South Africa with other countries

Ranked by flagged networks per million allocated IPv4 addresses.

Countries ranked next to South Africa by rate

#CountryNetworksPer million
54Venezuela345.07
55Finland705.00
56South Africa1314.82
57Sweden1514.78
58Taiwan1614.39
59Portugal294.33

Questions about South Africa

How many malicious IP addresses are there in South Africa?
On 2026-10-11, 131 IPv4 networks (/24 blocks) located in South Africa were flagged for malicious activity, with 933 listed IPv4 addresses and 2 IPv6 networks. Each /24 counts once, however many of its addresses are listed.
Which networks in South Africa host the most flagged IPs?
MEGASURF-WIRELESS-INTERNET (AS327991, 28 networks), AFRIHOST-SP (AS37611, 10 networks), NTT-DATA-Inc (AS20011, 9 networks). Large hosting providers appear because attackers rent their servers, not necessarily because of the operator.

Query this data per IP via the API

Look up threat categories, reputation score, ASN and geolocation for any address in South Africa or anywhere else with one API call.