FYI, I got this email for a non-exit relay - please share if you get them as 
well:



To Whom it May Concern,

You have a system on your network that is actively scanning and/or attacking 
external sites on the Internet. This can come from many sources and because it 
is often difficult to detect this activity, we are sending this E-mail in an 
attempt to help you solve the problem.

We have detected your system with an IP of, <relay-IP>, scanning a client we 
monitor. This was not a short attack but a prolonged scan and/or probe that was 
designed to find and intrude into the target network.

This may be someone on your network who is actively trying to hack others. This 
person may be a legitimate user on your network or it may be that this system 
has been compromised and is being used by someone to hack others. It is also 
likely that the system is running automated tools that have been installed to 
perform these actions without any human intervention.

Below is the information about the attack. Keep in mind that the source IP of 
our client has been sanitized for anonymity.

Date: 09/XX/2017
Time Zone: America/Chicago
Source(s): relay-IP
Type of Attack/Scan: Generic
Hosts: <RFC1918 IP address>
Log:

relay-IP:ORPort > RFC1918 IP address

Possible Cause:


Thank you for your attention to this matter,

Masergy
email: e...@masergy.com mailto:e...@masergy.com

---------------
_______________________________________________
tor-relays mailing list
tor-relays@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Reply via email to