We are experiencing a large number of distributed attacks on our
network. There isn't any one specific site being hit and the source
seems to be from many different IP addresses. We think this is a new
virus that is out. We are doing out best to stop it but it is not very
easy.
We'll let you know what we find out. We are working with our vendors
and partners to stop these issues. Here's examples below. We believe
these source IPs are faked.
Possible SYN Flood on IF X1 - src:
59.125.255.175:59425 - rate: 1013/
sec continues
Possible SYN Flood on IF X1 - src:
59.125.255.175:59425 - rate: 1013/
sec continues
Possible SYN Flood on IF X1 - src:
213.73.222.247:2584 - rate: 941/
sec continues
Possible SYN Flood on IF X1 - src:
65.26.70.29:33695 - rate: 946/sec
continues
Possible SYN Flood on IF X1 - src:
12.50.205.66:24667 - rate: 929/sec
continues
Possible SYN Flood on IF X1 - src:
72.231.187.142:49437 - rate: 1032/
sec continues
Possible SYN Flood on IF X1 - src:
72.231.187.142:49437 - rate: 1032/
sec continues
Possible SYN Flood on IF X1 - src:
76.125.103.211:43290 - rate: 1004/
sec continues
Thanks,
Marc Pope
Falcon Internet