In the last 10 days, approximately, I have been receiving this message, in part, from our server company:
"...has exceeded the notification threshold (90) for CPU Usage by averaging 98.5% for the last 2 hours."
At first I did not pay attention because I believed it was due to increased traffic for our coverage of several disease outbreaks. Then I noticed heavy traffic at non-peak times. Upon investigation I discovered an ip hitting hundreds of threads at the same time at the rate of more than 1 per minute. I banned this ip:
78.9.515.204
RIPE describes this ip as;
inetnum: 78.9.151.0 - 78.9.151.255
netname: DIALOGNET
descr: Dynamic Broadband Services
descr: Telefonia Dialog S.A. -
Dialog Telecom country: PL
admin-c: NT1264-RIPE
tech-c: NT1264-RIPE
status: ASSIGNED PA mnt-by: NETIA-MNT
created: 2011-01-04T15:18:39Z
last-modified: 2012-12-28T09:07:54Z
source: RIPE # Filtered
Apparently this is the telephone system in Poland. Obviously someone has hijacked a server and is using it for DDOS attacks.
DDOS attacks do not take us down anymore since we are in "the cloud" and mirrored. Resources are given to us as needed so we can stay up. You might notice that the site gets sticky - that is, the page seems to hang for a few seconds before progressing. It is clear this is a computer program because I can see a pattern to the hits. I do not know if we are specifically a target or included as a part of a larger program. Maybe these guys are hitting 100s or even 1000s of sites. I have no idea.
In any event, FluTrackers is not going to shut up. We will always find a way to stay online.
Many thanks to our great team!