Supposedly it has been confirmed the attack was from a Mirai botnet. This article has some good info on Mirai, unfortunately it has many attack vectors: https://www.incapsula.com/blog/malware-analysis-mirai-ddos-botnet.html
-----Original Message----- From: Af [mailto:[email protected]] On Behalf Of Larry Smith Sent: Monday, October 24, 2016 12:15 PM To: [email protected] Subject: Re: [AFMUG] dyn attack indicators On Mon October 24 2016 11:09, That One Guy /sarcasm wrote: > we are demoing a couple of netflow analysers since thursday, so we > have the networks traffic recorded from friday. Does anybody know what > specific criteria to look for to identify subscribers who may have been > involved? https://labs.ripe.net/Members/massimo_candela/a-quick-look-at-the-attack-on-dyn -- Larry Smith [email protected]
