You appear to be running an open SNMP server at IP address 107.161.118.168 that participated in an attack against a customer of ours, generating large UDP responses to spoofed queries, with those responses becoming fragmented because of their size.
Please consider reconfiguring your SNMP-speaking device in one or more of these ways:
- Block queries made by unauthorized addresses. This can be done with an ACL or other firewall rule.
- Use a different query string than "public" and which cannot be easily guessed by a 3rd party.
- Disable SNMP entirely.
If you are an ISP, please also look at your network configuration and make sure that you do not allow spoofed traffic (that pretends to be from external IP addresses) to leave the network. Hosts that allow spoofed traffic make possible this type of attack.
Example SNMP responses sent to us by your device during the attack are given below.
Date/timestamps (far left) are UTC.
2015-03-14 03:26:05.187035 IP (tos 0x0, ttl 56, id 0, offset 0, flags [DF], proto UDP (17), length 1305) 107.161.118.168.161 > 66.150.214.x.27015: UDP, length 1277
(The final octet of our customer's IP address is masked in the above output because some automatic parsers become confused when multiple IP addresses are included. The value of that octet is "141".)