Unexplained ‘Noise Storms’ flood the Internet, puzzle experts

Teilen:

Internet intelligence firm GreyNoise reports that it has been tracking large waves of “Noise Storms” containing spoofed internet traffic since January 2020. However, despite extensive analysis, it has not concluded its origin and purpose.

These Noise Storms are suspected to be covert communications, DDoS attack coordination signals, clandestine command and control (C2) channels of malware operations, or the result of a misconfiguration.

A curious aspect is the presence of a “LOVE” ASCII string in the generated ICMP packets, which adds further speculation as to their purpose and makes the case more intriguing.

GreyNoise published this information hoping the cybersecurity researchers community can help solve the mystery and uncover what’s causing these strange noise storms.

Characteristics of the noise storms

GreyNoise observes large waves of spoofed internet traffic coming from millions of spoofed IP addresses from various sources such as QQ, WeChat, and WePay.

The “storms” create massive traffic directed to specific internet service providers like Cogent, Lumen, and Hurricane Electric but avoid others, most notably Amazon Web Services (AWS).

The traffic mainly focuses on TCP connections, particularly targeting port 443, but there’s also an abundance of ICMP packets, lately including an embedded ASCII string “LOVE” within them, as shown below.

ICMP packets containing the "Love" string
ICMP packets containing the “Love” string
Quelle: BleepingComputer

The TCP traffic also adjusts parameters such as window sizes to emulate different operating systems, keeping the activity stealthy and difficult to pinpoint.

The Time to Live (TTL) values, which dictate how long a packet stays on the network before it’s discarded, are set between 120 and 200 to resemble realistic network hops.

All in all, the form and characteristics of these “noise storms” indicate a deliberate effort by a knowledgeable actor rather than a large-scale side effect of a misconfiguration.

GreyNoise calls for help

This strange traffic mimics legitimate data streams, and while it’s not known if it’s malicious, its true purpose remains a mystery.

GreyNoise published packet captures (PCAPs) for two recent noise storm events on GitHub, inviting cybersecurity researchers to join in the investigation and contribute their insights or independent discoveries that will help solve this mystery.

“Noise Storms are a reminder that threats can manifest in unusual and bizarre ways, highlighting the need for adaptive strategies and tools that go beyond traditional security measures,” underlines GreyNoise.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:24 am, Jan. 25, 2025
Wetter-Symbol 8°C
L: 7° | H: 9°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 89 %
Druck: 1000 mb
Wind: 7 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:48 am
Sonnenuntergang: 4:36 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 9°°C 1 mm 100% 7 mph 92 % 1010 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 8°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 23 mph 92 % 983 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
8° | 9°°C 1 mm 100% 20 mph 84 % 995 mb 0 mm/h
Mi. Jan. 29 9:00 pm
Wetter-Symbol
5° | 8°°C 1 mm 100% 19 mph 90 % 1000 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
6° | 7°°C 0 mm 0% 4 mph 90 % 1000 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 5°°C 1 mm 100% 7 mph 92 % 1001 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 5°°C 0.59 mm 59% 6 mph 73 % 1004 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
6° | 6°°C 0.22 mm 22% 7 mph 55 % 1006 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 4 mph 56 % 1008 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 70 % 1009 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 73 % 1010 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 5 mph 71 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,724.90
1.04%
Ethereum(ETH)
€3,147.23
-0.58%
XRP(XRP)
€2.96
0.39%
Fesseln(USDT)
€0.95
-0.02%
Solana(SOL)
€240.12
-0.81%
USDC(USDC)
€0.95
0.00%
Dogecoin(DOGE)
€0.332966
-0.34%
Shiba Inu(SHIB)
€0.000019
-0.87%
Pepe(PEPE)
€0.000014
-2.25%
Peanut das Eichhörnchen(PNUT)
€0.341611
3.03%
Nach oben scrollen