Navigating the Digital Storm

Internet Weather Report

/

Archive

/

Category: Updates

  • DDoS botnet scans have been detected in the last 24 hours from the following IP addresses, grouped by ASN: ASN IP Address Country 701  71.127.248.52  US 701  100.33.50.34  US 1257  90.144.252.112  SE 2516  106.146.233.215  JP 2516  114.19.33.240  JP 2856  109.158.120.11  GB 3269  79.8.104.225  IT 3269  79.9.48.105  IT 3462  111.249.90.136  TW 3462  59.127.120.23  TW 3462  202.39.244.193  TW 3462  125.228.241.112  TW 3462  125.228.80.213  TW 3462  118.163.113.53  TW 3462  125.227.53.5  TW 3462  114.32.125.127  TW 3462  211.20.42.44  TW 3462  125.231.240.50  TW 3462  218.161.14.158  TW…

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • We’re detecting on uptick in GRE flood traffic. This traffic originates from DDoS botnets and abuses Generic Routing Encapsulation (GRE) packets to bombard their target. GRE traffic can be identified by looking for IP protocol number 47 in the packet header. GRE traffic is not UDP or TCP and can bypass some firewalls, if not filtered correctly. Further information on GRE can be found in RFC 2784 and RFC 2890.   Here’s a list of Source IP addresses we’ve recently…

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶