Ransom DDoS attack - need help!

Lyndon Nerenberg lyndon at orthanc.ca
Thu Dec 3 19:59:23 UTC 2015

> Afaik, the DDoS is "only" a UDP based one (or much of the attack), you should be able to mitigate
> some to much of the damage caused by filled pipes by blocking incomming UDP trafic at your ISP level.

This is the Armada Collective, based on the description.  We just went 
through a round with them. The hardest they were able to hit us peaked at 
a little under 80 Gbits/second. Primarily DNS and NTP amplification 
attacks. They also hit our web servers with a little over 80 million 
requests over a one hour period, and played some games with TCP to try to 
mess with the protocol stacks on the servers and network gear.

Cloudflare took care of the web attacks.  For DDoS, something like 
Incapsula will take care of the layer 3 stuff.  Not cheap, but very 


More information about the NANOG mailing list