Observation: with the beginning of the war against Iran, botnets more or less stopped attacking my mailserver. From typically 300–500 IP addresses per day it's now less than 5 since a week. Indicates that maybe quite some C&C (Command and Control) servers were operating from Iranian IP addresses and fell victim to the internet shutdown there.

#SysAdminLife @homelab

@jwildeboer @homelab Has there been previous lulls in the attacks? At least some graphs which have been floating around here indicated that Iran has been plugging the country out of internet quite a few times lately because of the protests.