I've recently been seeing darknet scans on our IPS and they all seem to be coming from android devices.
They are scanning non existent subnets on our network, and they are all using tcp 7 (echo). So far I have tracked several
devices with this type of traffic. Any thoughts on what can be causing this?