[tor-talk] Analyzing the (little) spike in relays on 2015-04-01 (Family at Choopa LLC)

Nusenu nusenu at openmailbox.org
Sun Apr 5 02:10:08 UTC 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

by looking at
https://metrics.torproject.org/platforms.html
https://metrics.torproject.org/versions.html
I noticed a little spike in relays at the beginning of the month
(actually I was visiting metrics to see if some ticket made progress ;)

On 2015-04-01 someone (it was likely a single entity) signed up 20
exits @ Choopa LLC. If you go back in time on that AS you find similar
events. So this potential entity might run 40 exits.
If you condense all properties and do not restrict your search to the
Choopa AS (AS20473) the potential operator likely runs 55 exits.

Fun part: Maxmind had no AS info on some IPs (4) that are also part of
AS20473, so they got filtered out in the first result set where I only
looked into AS20473 (40 relays), but these relays found there way back
into the result set (55 relays) on the next iteration due to other
similarities. So I'm pretty confident in the linkability of these exit
relays.

Details:
https://raw.githubusercontent.com/nusenu/misc-files/master/finding_the_hidden_choopa_family.txt


Common properties:
(ordered from more to less significant property)

- - *last_restarted*
- - first_seen (in groups)
- - DirPort (auto)
- - Nickname (not matching put similar naming style)
- - exit policy
- - no declared family
- - ORPort
- - two instances per IP
- - no contactInfo
- - tor version
- - os

Can someone make some sense out of these nicknames?











-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJVIJmAAAoJEFv7XvVCELh0dXgQAIN5DkONb7MtCsYF6W/6fi2B
rdpBrAlhYJw11YuOqq4Z2VsFIBDqFs2Uwnq/r8Uat+bqjXkSE3VKKQJqnR2S2uf4
6LlTpLxNspf6ZshvQzhp7/jdiCPnPhIoIu3TRmp76sy8q8MDiHh8MzjWtDTYnWvu
XyeV++oPmlJYGsLwWEklIOKTAt6VqvLRjAXmMe6jpBhhCsthsO+NEQDZwXnCdDOe
toIGnprDP2otn8/D2TLDkAV4xeGXLUmbrOjyBij8DQEfGNSKnpExbBTbhLi0gLv6
ynlVRPhTM9QJzvlJ2q/U6IKwbBLJAstFAT7Xf8GbEtzF4ax+v0kKcsopyqNQpeUl
xf1+SkKk0wjNZ4BPB1sDFXQBbfN8yp/L0oyoSB+vzTVAHw8A5aqwJ/s2XtlkDNb+
zZJehL7FWgDeRypN6LsXN77onggy6Wfe+vkE/WybwWd9ITsw/EWYB9LAc3Dd4sat
W56DteamsdfS738N+j+jG+plJ6xBHF57zebdLi3OcH6SlDDkpKaRUJAV/bbWh/z9
Q7VDuYj7mjaCH8dPbWzQp1fZcWTBTrWn8pCi5DiwDyTzJC53w2lRCtwzMCPzTVAA
j1aDe95Io+FTNgczp3jQcyfMQskeclJJD6v26kDKrBbNPXjELUPy+/sLiHhMj3M2
xUlJ23mJhcG78HrIzcBV
=mVqg
-----END PGP SIGNATURE-----


More information about the tor-talk mailing list