any help in killing clients welcome. thanks. flows to 204.181.64.0/24, looks like TCP/80 traffic (HTTP malformed) and other standard attack junk. _____________________________ jose nazario, ph.d. jose at arbor.net sr. manager of security research, arbor networks http://asert.arbor.net/