Unexplained ‘Noise Storms’ flood the Internet, puzzle experts
ID: 37dcfb5e-29d8-5dda-8c39-3b1eddc269f9
STIX ID: report--37dcfb5e-29d8-5dda-8c39-3b1eddc269f9
Feed Name: Bleeping Computer
GreyNoise has observed recurring large waves of spoofed internet traffic called “Noise Storms” that originate from millions of spoofed IPs, concentrate on certain ISPs (e.g., Cogent, Lumen, Hurricane Electric), target TCP (notably port 443) and ICMP (recently containing an embedded "LOVE" ASCII string), and use packet attributes (TTL, window sizes) to mimic real hosts; GreyNoise released PCAPs and requests community assistance to determine whether this is covert comms, DDoS coordination, clandestine C2 activity, or a misconfiguration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
