FINDING · DETECTION

Over 3295 active-probing scans observed across 17 days, 51% (1680) originated from a single IP address (202.108.181.70), while 98% of the remaining 1615 addresses were unique. All scanner IPs belong to three Chinese ASes: AS4837 (65.7%), AS4134 (30.5%), and AS17622 (3.8%). TTL analysis of 85 connections shows the scanner IPs are likely spoofed by the GFC—post-scan ping TTLs differed by +1 from during-scan TTLs.

From 2012-winter-greatHow the Great Firewall of China is Blocking Tor · §4.5 · 2012 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
active-probing
defenses
torbridges

Extracted by claude-sonnet-4-6 — review before relying.