> This traffic started on my network on Feb. 2nd, at 7:00AM EST STD time.
> They all originate from, all with a source port of 6667
> TCP, the destination is my entire class B on TCP ports 1024 and 3072.
> All packets are RST/ACK.  Anyone else seeing this IP hitting their
> network?  Looks like someone is spoofing our address space, and I have
> confirmed that at least one other University is seeing this.

Looks like backscatter from someone doing a spoofed source SYN flood on  I see similar types of traffic from time to time.

