@drewdevault Out of honest curiosity: can you report any of these networks to their ISP? If an attack remains ongoing for long enough there’s (a) a chance for forensic analysis of what’s going on (b) an chance to actually cut it out from the source (likely some compromised system).
I’m aware that some just come from lawless regions, but some must come from places where law enforcement kind cares, right?
@drewdevault Is there no law enforcement branch that has this in scope? I’d assume that some of the hosts in the botnet are in the EU, right?
Obviously for something that lasts an hour nobody’s gonna do anything. But for a sustained attack that lasts for days/weeks; there’s definitely something actionable to be done (ISPs informing clients that they’re a botnet, analysis on compromised devices, etc).