Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

DDoS Effecting AVS ISP

avsispavsisp Member, Patron Provider

Hello,

We are facing right now a massive DDoS that is hitting all of our locations at the same time. We are entirely offline in multiple locations. We are attempting to get things back online as quickly as possible, but there isn't much we can do.

Attack is hitting several TB/s and several Gpps in total across locations.

NL seems to be online and is being scrubbed by GSL - UK seems to be running scrubbing as best as it can.

AL and MK are entirely offline.

We have no updates at this time. Please do not submit tickets or email asking about things being offline - our teams are per-occupied with attempting to mitigate the attacks and you may not receive a reply until it ends. Time taken for tickets and emails is time taken from mitigation efforts at this time.

Thank you for understanding.

Thanked by 3nghialele zGato Murv

Comments

  • Submitted 45 work orders & am losing millions (of packets)

  • rpqurpqu Member

    @avsisp is it Iran

  • LeviLevi Member

    Just nullroute. Attackers take satisfaction from scrub efforts, change tactics, play games. Null route, wait for 12 hours.

  • nikionikio Member

    Interesting coincidence with the RS-Computers merger.

    Thanked by 3oloke rpqu buggedout
  • MurvMurv Member, Megathread Squad

    @rpqu said:
    @avsisp is it Iran

    You break my IP spoofing heart

  • I am losing gazillions of Zimbabwean dollarz in Albanique location.

  • avsispavsisp Member, Patron Provider

    UPDATE: Everything is back online and rerouted over GSL scrubbing centers.

    We will update anyone who submitted tickets or emails shortly.

    Thank you for your patience and understanding.

    Thanked by 3JohnFilch123 Murv atomi
  • avsispavsisp Member, Patron Provider

    @rpqu said:
    @avsisp is it Iran

    Not likely.

    Attacker is believed to be based in Russia and be government affiliated.

    Right before the attack began, we started to get reports of some of our IPs being blocked in Russia. Not long after, we had a flood of port scans from Russian IPs. And following this, the attack began with Russian origin traffic before moving to global. The attack also first targeted NL - where we host a few Russia based VPN services and anti-censorship services.

    Attacks of this scale, in the TB/s & multiple-Gpps tend to be nation-state actors or those affiliated with them in some manor.

    Though we can't confirm details at this point and it's just a hunch based on the events leading up to the attack - we do NOT believe this to be Iranian sourced.

    Thanked by 3rpqu Murv skimply153
  • avsispavsisp Member, Patron Provider

    @Levi said:
    Just nullroute. Attackers take satisfaction from scrub efforts, change tactics, play games. Null route, wait for 12 hours.

    Nullrouting leaves our clients offline. We pay for professional mitigation services like GSL and Pletx for a reason - to not have clients offline. If you nullroute, you just give them the win.

  • avsispavsisp Member, Patron Provider

    @nikio said:
    Interesting coincidence with the RS-Computers merger.

    Coincidence it is - the merger has been ongoing for months now and the clients being moved has been 3 days ongoing. It's just a coincidence - nothing more. And RS prefixes were NOT targeted at this time.

  • icemaniceman Member
    edited 2:07PM

    @avsisp said:

    @rpqu said:
    @avsisp is it Iran

    Not likely.

    Attacker is believed to be based in Russia and be government affiliated.

    Right before the attack began, we started to get reports of some of our IPs being blocked in Russia. Not long after, we had a flood of port scans from Russian IPs. And following this, the attack began with Russian origin traffic before moving to global. The attack also first targeted NL - where we host a few Russia based VPN services and anti-censorship services.

    Attacks of this scale, in the TB/s & multiple-Gpps tend to be nation-state actors or those affiliated with them in some manor.

    Though we can't confirm details at this point and it's just a hunch based on the events leading up to the attack - we do NOT believe this to be Iranian sourced.

    Thanks God for having Russia like it is, so that we can blame for our incompetence and everything ;) i mean, government state sponsored to attack you? Cmon, do you really think that we are that delusional?! And who is "we"?

  • @avsisp said: where we host a few Russia based VPN services and anti-censorship services

    Then it's just competitors because there are hundreds of services like that.
    Basically it's impossible to use the internet there without VPN, just like in China and Iran.

  • AlyxAlyx Member, Host Rep
    edited 2:13PM

    How every attack is supposedly a state-sponsored act nowadays 😅

    Thanked by 1luckypenguin
Sign In or Register to comment.