Shodan scan found my KnownHost dedicated box with IPMI wide open. Factory ADMIN/ADMIN. In my experience, Windows Server's built-in firewall would have blocked the BMC subnet but I was running bare Linux with no iptables rules on that interface. Attacker had SOL redirection active for eleven hours before I noticed. They were mounting ISOs over the virtual media channel. To be fair, this is entirely my fault for not checking the delivery checklist. Lesson: always change IPMI creds before racking, always VLAN it separately, always audit with nmap from outside. The datacenter swore they "pre-secured" everything. They did not.
Have you tried restarting it?