Filtering is being done by eg This hop is after my source's ISP. The filtering IPs are owned by ITC, Iran's central telco. It's http://bgp.he.net/AS12880 (h/t to Tor team for that).

Filtering targets all google.com IPs, some but not all torproject.org IPs, probably more. Haven't attempted a broad scan. It's a simple connection drop; filtered connections just time out.

It is not based on SSL handshake signature; testing SSL on nonstandard ports worked successfully, and testing non-SSL on :443 of target IPs was blocked.

