Looks like we now have confirmation that the spoofed source IPs port 22 scanning is a deliberate attack against Tor relays: https://r00t.monster/
It's kind of funny and sad how the attacker is so alone and so bad at PR that it took more than a week for anyone to notice their webpage, all the while they've been hard at work seething and screenshotting everything like a maniac. F