VORANT. Threat Intelligence Sign in Get the full feed

TSUBAME sensors log Iran traffic drop amid conflict

low vulnerability telecommunicationsfinancial-servicesmedia

JPCERT's TSUBAME sensor network observed a sharp drop in Iranian source IP addresses during the June 2025 Israel-Iran conflict, likely due to internet restrictions after cyberattacks on Iranian banks and media.

JPCERT's Q2 2025 TSUBAME Report Overflow covers global sensor monitoring trends from April to June 2025, with a focus on packet fluctuations from Iran coinciding with the Israel-Iran military conflict. Between June 13 and 27, the daily count of unique source IP addresses from Iran dropped significantly from a typical baseline of 170-200 to as low as 20-100, while Israeli source IP counts remained stable. Media reports cited in the article indicate cyberattacks targeted Iran's state broadcaster, banks, and cryptocurrency exchanges around June 18, and the Iranian government reportedly restricted internet connectivity in response, which JPCERT suggests explains the observed decline in scanning traffic.

The report also provides routine comparative monitoring data, noting that both domestic (Japan) and overseas sensors peaked in packet volume in April with a gradual decline through June. Across nearly all sensors, ports 22/TCP, 23/TCP, 80/TCP, 443/TCP, and 8080/TCP remained the most frequently scanned, indicating widespread opportunistic scanning of these common services. No specific vulnerabilities, malware, or named threat actors were identified in this reporting period; the piece is primarily an informational/trend-monitoring update rather than an active threat disclosure.

Source reporting: https://blogs.jpcert.or.jp/en/2025/10/tsubame_overflow_2025-04-06.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free