The last week, I have seen an increase in ICMP Echo requests from Iran to my two Honeynets (on different networks here in Norway). Special about this, is that they ping every hosts on the network, with a TTL starting between 85 to 231 and decreasing to 0. Then it seems that they keep on pinging hosts on the networks that they found, about once each 2. day after that, but from new hosts, in the same network.
My guess is, that its a mapping of the network of some kind, but for what, we will have to wait and see 🙂
IP’s involved that I see are from the nets: 220.127.116.11/24 and 18.104.22.168/24 which are both in the net 22.214.171.124/19 which seems to belong to:
inetnum: 126.96.36.199 – 188.8.131.52
descr: Sharif University Of Technology
descr: PROVIDER LOCAL REGISTRY