IRCaBot 2.1.0
GPLv3 © acetone, 2021-2022
#saltr
/2024/12/17
~dr|z3d
@RN
@StormyCloud
@T3s|4_
@eyedeekay
@postman
@zzz
+FreefallHeavens_
+Xeha
+acetone
+bak83_
+hk
+profetikla
+r00tobo_BNC
+snex
+uop23ip
+weko
Arch
Danny
DeltaOreo
Irc2PGuest12249
Irc2PGuest17978
Irc2PGuest25220
Irc2PGuest90883
Irc2PGuest92478
Leopold_
Liorar
Meow
Nausicaa
Onn4l7h
Onn4|7h
aisle1
anu3
ardu
boonst
deadface
dickless
duck
enoxa
evasiveStillness
foobar_
mareki2pb
maylay
not_bob_afk
orignal_
poriori_
qend-irc2p
radakayot_
shiver_
simprelay
solidx66
u5657
usr001
woodwose
orignal guys, what can you say about router jhyi ?
orignal bunch of transit tunnels and all empty
dr|z3d banned here.
dr|z3d keep an eye on it, you'll also see it rapidly cycling ips.
orignal yes it is
orignal they question is why so many tunnels through it
zzz yeah drz caught it a month ago
orignal esepcially since it's LU
orignal the question is about number of tunnels
orignal who builds it
orignal or there are execissve amount of such duplicates
dr|z3d it's quite likely malicious
dr|z3d if you look at the ips, they're not coming from a commercial vpn. they're all residential. it may be the cc of that malware zzz flagged a while back.
orignal and we don't recognize it as multihomes
orignal because no conflict with netdb
orignal seems they really change ip all the time
dr|z3d "i2predia" iirc.
dr|z3d link's up on ramble if you missed it.
orignal what's that?
dr|z3d i2p-hosted malware.
orignal that's fine but why it affects tunnels?
orignal looks like it never accepts tunnels
orignal and secons thing who chooses the one for tunnel
dr|z3d there are 4 or 5 doing exactly the same thing on the network.