Happy New Year! Let the botnets loose!

Jack Bates jbates at brightok.net
Fri Jan 2 20:23:14 UTC 2009

 From reports in the CBL database, it appears they have enjoyed some DOS 
traffic yesterday, and I'm currently enjoying a little 40k+ botnet 
attack (small botnet beats large one when you host the victim IP).

Anyone have any good resources on the breakdowns of the current known 
botnets and their traffic patterns? This one appears to use random IP 
protocol numbers, and extremely small packets. IP 255 and ICMP type 70 
seem popular on this one, but I see a lot of randomness.

Feel free to reply offlist if you have some good resources.

Jack Bates

More information about the NANOG mailing list