On 2026-09-13 03:26, Red Oaive wrote:
I now have a repeat customer re-attacking a relay I manage in the same way. I'm going to do what I can to trace it before I turn off the DirCache again.
Ok, the attack seems to be distributed, but it looks to have a relatively small number of participating relays. Here are relays that look like they are participating: 74.106.232.4 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 107.173.7.218 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 45.137.100.160 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 136.243.175.182 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 172.104.234.114 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 213.95.55.63 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 82.126.182.66 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 192.186.127.123 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 109.255.184.38 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 78.43.117.254 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 172.233.242.114 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 207.180.192.66 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 172.232.111.152 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... [2600:3c01:e000:3a0::] ??? Cannot find a relay with this address in the consensus but shows up in my list. Notes: 1) MOST but not all are reporting they are outdated Tor versions. 2) They all self-report as low bandwidth servers and show data graphs with low data flow. However, my relay is at this moment sending multiple megabytes per second to each one, enough to single handedly far exceed their entire reported data flow. 3) Many of them have very similar data graph shapes 4) The above are not all nodes that are participating, but all the ones that are that I have high confidence. There are less than 40 in total that are participating. Lastly, there are a few nodes that are participating which are odd: 140.78.100.35 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.htm... 140.78.100.28, 37, 38 These self report as being part of a large tor research project for looking into onion services and each identifies a URL for the research project: https://www.digidow.eu/experiments/onion-stats/ The URL looks legitimate but the nodes in question are absolutely showing the exact same characteristic data graph shape, shows a data flow of 80k/s but where they are actually sinking about 1-2MiB/s from my relay as I write this.