Supposedly it has been confirmed the attack was from a Mirai botnet.  This 
article has some good info on Mirai, unfortunately it has many attack vectors:
https://www.incapsula.com/blog/malware-analysis-mirai-ddos-botnet.html


-----Original Message-----
From: Af [mailto:[email protected]] On Behalf Of Larry Smith
Sent: Monday, October 24, 2016 12:15 PM
To: [email protected]
Subject: Re: [AFMUG] dyn attack indicators

On Mon October 24 2016 11:09, That One Guy /sarcasm wrote:
> we are demoing a couple of netflow analysers since thursday, so we 
> have the networks traffic recorded from friday. Does anybody know what 
> specific criteria to look for to identify subscribers who may have been 
> involved?

https://labs.ripe.net/Members/massimo_candela/a-quick-look-at-the-attack-on-dyn

--
Larry Smith
[email protected]


Reply via email to