Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

DDoS Effecting AVS ISP

avsispavsisp Member, Patron Provider

Hello,

We are facing right now a massive DDoS that is hitting all of our locations at the same time. We are entirely offline in multiple locations. We are attempting to get things back online as quickly as possible, but there isn't much we can do.

Attack is hitting several TB/s and several Gpps in total across locations.

NL seems to be online and is being scrubbed by GSL - UK seems to be running scrubbing as best as it can.

AL and MK are entirely offline.

We have no updates at this time. Please do not submit tickets or email asking about things being offline - our teams are per-occupied with attempting to mitigate the attacks and you may not receive a reply until it ends. Time taken for tickets and emails is time taken from mitigation efforts at this time.

Thank you for understanding.

Thanked by 3nghialele zGato Murv

Comments

  • Submitted 45 work orders & am losing millions (of packets)

  • rpqurpqu Member

    @avsisp is it Iran

  • LeviLevi Member

    Just nullroute. Attackers take satisfaction from scrub efforts, change tactics, play games. Null route, wait for 12 hours.

  • nikionikio Member

    Interesting coincidence with the RS-Computers merger.

    Thanked by 3oloke rpqu buggedout
  • MurvMurv Member, Megathread Squad

    @rpqu said:
    @avsisp is it Iran

    You break my IP spoofing heart

  • I am losing gazillions of Zimbabwean dollarz in Albanique location.

  • avsispavsisp Member, Patron Provider

    UPDATE: Everything is back online and rerouted over GSL scrubbing centers.

    We will update anyone who submitted tickets or emails shortly.

    Thank you for your patience and understanding.

  • avsispavsisp Member, Patron Provider

    @rpqu said:
    @avsisp is it Iran

    Not likely.

    Attacker is believed to be based in Russia and be government affiliated.

    Right before the attack began, we started to get reports of some of our IPs being blocked in Russia. Not long after, we had a flood of port scans from Russian IPs. And following this, the attack began with Russian origin traffic before moving to global. The attack also first targeted NL - where we host a few Russia based VPN services and anti-censorship services.

    Attacks of this scale, in the TB/s & multiple-Gpps tend to be nation-state actors or those affiliated with them in some manor.

    Though we can't confirm details at this point and it's just a hunch based on the events leading up to the attack - we do NOT believe this to be Iranian sourced.

    Thanked by 3rpqu Murv skimply153
  • avsispavsisp Member, Patron Provider

    @Levi said:
    Just nullroute. Attackers take satisfaction from scrub efforts, change tactics, play games. Null route, wait for 12 hours.

    Nullrouting leaves our clients offline. We pay for professional mitigation services like GSL and Pletx for a reason - to not have clients offline. If you nullroute, you just give them the win.

    Thanked by 1VTCuong
  • avsispavsisp Member, Patron Provider

    @nikio said:
    Interesting coincidence with the RS-Computers merger.

    Coincidence it is - the merger has been ongoing for months now and the clients being moved has been 3 days ongoing. It's just a coincidence - nothing more. And RS prefixes were NOT targeted at this time.

  • icemaniceman Member
    edited 2:07PM

    @avsisp said:

    @rpqu said:
    @avsisp is it Iran

    Not likely.

    Attacker is believed to be based in Russia and be government affiliated.

    Right before the attack began, we started to get reports of some of our IPs being blocked in Russia. Not long after, we had a flood of port scans from Russian IPs. And following this, the attack began with Russian origin traffic before moving to global. The attack also first targeted NL - where we host a few Russia based VPN services and anti-censorship services.

    Attacks of this scale, in the TB/s & multiple-Gpps tend to be nation-state actors or those affiliated with them in some manor.

    Though we can't confirm details at this point and it's just a hunch based on the events leading up to the attack - we do NOT believe this to be Iranian sourced.

    Thanks God for having Russia like it is, so that we can blame for our incompetence and everything ;) i mean, government state sponsored to attack you? Cmon, do you really think that we are that delusional?! And who is "we"?

  • @avsisp said: where we host a few Russia based VPN services and anti-censorship services

    Then it's just competitors because there are hundreds of services like that.
    Basically it's impossible to use the internet there without VPN, just like in China and Iran.

  • AlyxAlyx Member, Host Rep
    edited 2:13PM

    How every attack is supposedly a state-sponsored act nowadays 😅

  • rpqurpqu Member
    edited 2:16PM

    @Alyx said:
    How every attack is supposedly a state-sponsored act nowadays 😅

    Being indie is hard these decade. Gotta get corporate state sponsorship

    Thanked by 1Alyx
  • tentortentor Member, Host Rep

    @Alyx said:
    How every attack is supposedly a state-sponsored act nowadays 😅

    I don't think 30Tbps Minecraft DDoSes were tho.

    Thanked by 3Alyx rpqu oloke
  • VTCuongVTCuong Member

    Deluxhost also just got DDoSed recently, also used GSL for traffic scrubbing, so hard that they dropped the majority of legitimate traffic, while left their customers in the dark 🤦.

    @avsisp said:
    Attacker is believed to be based in Russia and be government affiliated.

    Russian state sponsored groups pull off shits like tampering with GPS signals and fighting Ukrainian drones, not DDoSing some random host, you're not that special dawg. Mr. @luckypenguin is right, there's just so many competitors in Netherlands that they had to play dirty to keep the cost high.

  • avsispavsisp Member, Patron Provider

    @VTCuong said:
    Deluxhost also just got DDoSed recently, also used GSL for traffic scrubbing, so hard that they dropped the majority of legitimate traffic, while left their customers in the dark 🤦.

    @avsisp said:
    Attacker is believed to be based in Russia and be government affiliated.

    Russian state sponsored groups pull off shits like tampering with GPS signals and fighting Ukrainian drones, not DDoSing some random host, you're not that special dawg. Mr. @luckypenguin is right, there's just so many competitors in Netherlands that they had to play dirty to keep the cost high.

    Again, if you read the entire message there, you'd see the signs that led to the conclusion, along with a disclaimer that we aren't sure 100% and that it's just where the signs point.

    The only reason we didn't say it was just Russian sourced and that we believe it to be state actor is that right before it happened, a lot of our IPs were apparently added to the famous Russian drop lists - with traffic being blackholed by all Russian ISPs - something only the Government can order - not a citizen.

  • avsispavsisp Member, Patron Provider
    edited 3:25PM

    @iceman said:

    @avsisp said:

    @rpqu said:
    @avsisp is it Iran

    Not likely.

    Attacker is believed to be based in Russia and be government affiliated.

    Right before the attack began, we started to get reports of some of our IPs being blocked in Russia. Not long after, we had a flood of port scans from Russian IPs. And following this, the attack began with Russian origin traffic before moving to global. The attack also first targeted NL - where we host a few Russia based VPN services and anti-censorship services.

    Attacks of this scale, in the TB/s & multiple-Gpps tend to be nation-state actors or those affiliated with them in some manor.

    Though we can't confirm details at this point and it's just a hunch based on the events leading up to the attack - we do NOT believe this to be Iranian sourced.

    Thanks God for having Russia like it is, so that we can blame for our incompetence and everything ;) i mean, government state sponsored to attack you? Cmon, do you really think that we are that delusional?! And who is "we"?

    Do you never get tired of trolling? This will be our 1 and only reply to you - move along. Everyone here knows who you are, that you don't like us, and that you like to make issues. Enjoy the rest of your day.

  • avsispavsisp Member, Patron Provider

    @Alyx said:
    How every attack is supposedly a state-sponsored act nowadays 😅

    Only when it comes with the blackholing your IPs in their country right before, only for the blackhole to be lifted and DDoS to slam you hours after and the blackhole to be put back into place not long after for a large subset of your IPs.

  • @avsisp said: a lot of our IPs were apparently added to the famous Russian drop lists - with traffic being blackholed by all Russian ISPs

    That's a sign that you host public VPN services focused on russian users. They detect multiple RU sources connecting to the same IP with large traffic volumes and block it.
    The government doesn't order anything, it's a semi-automated system like DPI.
    From that, to jump to a conclusion it was a state sponsored attack was a huge stretch :)
    They have a fuel crisis now, not exactly the perfect timing to DDoS a small Albanian ISP.

  • avsispavsisp Member, Patron Provider

    @luckypenguin said:

    @avsisp said: a lot of our IPs were apparently added to the famous Russian drop lists - with traffic being blackholed by all Russian ISPs

    That's a sign that you host public VPN services focused on russian users. They detect multiple RU sources connecting to the same IP with large traffic volumes and block it.
    The government doesn't order anything, it's a semi-automated system like DPI.
    From that, to jump to a conclusion it was a state sponsored attack was a huge stretch :)
    They have a fuel crisis now, not exactly the perfect timing to DDoS a small Albanian ISP.

    Again, we said we suspect it to be. We gave the signs. The biggest isn't only that they blackholed it - but that they un-blackholed it long enough to start a full blown DDoS - which only the government can turn those blocks on and off at will. The majority of that source traffic came across links with high Russian ISPs - like links using GNM-IX for example.

    We've not given a definitive "IT'S THEM, THEY DID IT" - we gave the signs and our opinion on where we believe it originates along with a "we can't prove it, but we suspect" disclaimer.

Sign In or Register to comment.