We started seeing this around the 9th I believe. We were not the only people as well, based on a somewhat late ISC post[1].

We thought it was a new form of intelligent blackholing. Instead of sending traffic to IPs that could easily be blacklisted by tools to get around the firewall, the Great Firewall would start sending them to random "good" IPs for the same result. Others seem to think the same thing[2].

[1] https://isc.sans.edu/forums/diary/Are+You+Piratebay+thepirat... [2] https://en.greatfire.org/blog/2015/jan/gfw-upgrade-fail-visi...

