If this was an attempted reflection attack, it was highly ineffective.  1024
packets over the course of six and a half hours?

I just checked: the distribution is not uniform; some IPs have more hits
than others, and there are some that were omitted.  Also, because our
firewall normally permits icmp type 3 packets to pass through, packets
targetted to addresses with static mappings in the firewall were neither
blocked nor logged by the firewall.  


> Another alternative explanation is that you were either the target
> of, or an unwitting bystander to, a DDOS attack.  
> Say I spoofed one of your addresses (or even worse, your "broadcast"
> address) and sent pings to some address behind one of the routers you
> listed.  Since I used your address to send the packet, the
> host-unreachable would come back to you, not me.  If I had a hundred
> machines all doing this, the host-unreachable messages coming back at
> you from all directions could cause havoc.  
> It is not unknown to use something like this to overwhelm admins or
> intrusion detection systems while another, more precise, attack is
> going on...  such as hunting for a vulnerable SMTP host.  It wouldn't
> make much sense to use this to hide a scan for on open relay though,
> as that's such a quick scan.
