[nsp-sec] UDP DDoS

Dave Monnier dmonnier at cymru.com
Tue Mar 13 15:25:10 EDT 2012


Team,

Looking for the source of a UDP-based attack against these IP:

202.163.115.10
202.163.115.11
61.5.158.117
61.5.158.121
61.5.158.124
61.5.158.114

Leaders by percentage look to be:
36351   | 173.192.220.101  | SOFTLAYER - SoftLayer Technologies Inc.
36351   | 173.192.222.69   | SOFTLAYER - SoftLayer Technologies Inc.
36351   | 208.43.81.118    | SOFTLAYER - SoftLayer Technologies Inc.
21844   | 174.120.229.130  | THEPLANET-AS - ThePlanet.com Internet
19066   | 173.199.150.228  | WIREDTREE - Cogswell Enterprises Inc.
30217   | 216.87.163.170   | DESYNC - Desync Networks

SRC/DST ports are all over.

Thanks!
-Dave

-- 
Dave Monnier
Team Cymru
https://www.team-cymru.org/
PGP: https://www.cymru.com/dmonnier/0x7C1AAE55_pub.asc


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: OpenPGP digital signature
URL: <https://puck.nether.net/mailman/private/nsp-security/attachments/20120313/7050624c/attachment-0001.sig>


More information about the nsp-security mailing list