-
DDoS botnet scans have been detected in the last 24 hours from the following IP addresses, grouped by ASN: ASN IP Address Country 701 71.127.248.52 US 701 100.33.50.34 US 1257 90.144.252.112 SE 2516 106.146.233.215 JP 2516 114.19.33.240 JP 2856 109.158.120.11 GB 3269 79.8.104.225 IT 3269 79.9.48.105 IT 3462 111.249.90.136 TW 3462 59.127.120.23 TW 3462 202.39.244.193 TW 3462 125.228.241.112 TW 3462 125.228.80.213 TW 3462 118.163.113.53 TW 3462 125.227.53.5 TW 3462 114.32.125.127 TW 3462 211.20.42.44 TW 3462 125.231.240.50 TW 3462 218.161.14.158 TW…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
We’re detecting on uptick in GRE flood traffic. This traffic originates from DDoS botnets and abuses Generic Routing Encapsulation (GRE) packets to bombard their target. GRE traffic can be identified by looking for IP protocol number 47 in the packet header. GRE traffic is not UDP or TCP and can bypass some firewalls, if not filtered correctly. Further information on GRE can be found in RFC 2784 and RFC 2890. Here’s a list of Source IP addresses we’ve recently…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


