@RN
@RN_
@StormyCloud
@eyedeekay
@postman
@zzz
%Liorar
%cumlord
+FreefallHeavens
+HowardPlayzOfAdmin
+Onn4l7h
+Over
+bak83_
+poriori
+profetikla
+qend-irc2p
+r00tobo_BNC
+uop23ip
Arch
BubbRubb1
Danny
DeltaOreo
H20
Irc2PGuest10122
Irc2PGuest18100
Irc2PGuest63380
Irc2PGuest85653
Meow
T3s|4
ac9f
acetone_
anontor
dr|z3d
duck
halloy13412
leopold
mahlay
makoto
mareki2p_
nZDoYBkF__
nilbog-
not_bob_afk
ntty
orignal_
r00tobo[2]
shiver_
simprelay
solidx66_
thetia
tr
u5657
zer0bitz
orignal
guys, what can you say about router jhyi ?
orignal
bunch of transit tunnels and all empty
dr|z3d
banned here.
dr|z3d
keep an eye on it, you'll also see it rapidly cycling ips.
orignal
yes it is
orignal
they question is why so many tunnels through it
zzz
yeah drz caught it a month ago
orignal
esepcially since it's LU
orignal
the question is about number of tunnels
orignal
who builds it
orignal
or there are execissve amount of such duplicates
dr|z3d
it's quite likely malicious
dr|z3d
if you look at the ips, they're not coming from a commercial vpn. they're all residential. it may be the cc of that malware zzz flagged a while back.
orignal
and we don't recognize it as multihomes
orignal
because no conflict with netdb
orignal
seems they really change ip all the time
dr|z3d
"i2predia" iirc.
dr|z3d
link's up on ramble if you missed it.
orignal
what's that?
dr|z3d
i2p-hosted malware.
orignal
that's fine but why it affects tunnels?
orignal
looks like it never accepts tunnels
orignal
and secons thing who chooses the one for tunnel
dr|z3d
there are 4 or 5 doing exactly the same thing on the network.