In any case I wouldn't think much of it. If you obsess over any garbage traffic you get you will go insane.
In any case I wouldn't think much of it. If you obsess over any garbage traffic you get you will go insane.
There may be more realistic ways to go about protecting people's SSH servers that trying to dox Cloudflare VPN users.
I think OP guessed it was probably not Cloudflare themselves scanning their ports, so I think that's what they meant by "hear who and why".
Maybe dox is too strong a word. My point is, from what I've heard, the general sentiment is that you're unlikely to get any information about customers just by sending abuse reports to Cloudflare.
I used to spend time on custom iptables scripts but came to the conclusion it’s much better to just architect things in a way where the bots and scanners can’t plausibly create a problem and then ignoring them.
Some of my servers don't even have any IPv4 connectivity and there haven't been any failed SSH logins over IPv6.
*tarpit
A honeypot lets people "in" to see/research malware that's in the wild:
* https://en.wikipedia.org/wiki/Honeypot_(computing)
A tarpit just takes up the attacker's resources: