Conversation
Notices
-
Concurrent with the recent missile attack, Iran did some attempt at botnet; I don't know if details came out. But I'd made some remarks on IRC that there was a weird uptick in .ir IPs trying low-effort ssh brute-force attacks. So I'd said in a thread on fedi that this was weird: you run some machines that have public IPs and just watch and you see a lot of weird stuff, you can tell something is going down but maybe can't say *what* it is that is going down, you just know that something is up and if nothing has changed recently, then something is coming up in the next couple of weeks.
So, more .ir IPs today. That's odd.