These nodes are popping up everywhere - is this some sort of malware being deployed on systems around the globe?
Interesting. It does look like malware to me.
- all running Tor 0.3.1.7 on Linux - diverse AS / IP allocation, mostly looks like ISP end-subscriber - same exit policy (reject *:*)