@anurag_bhatia That seems to line up on our side as well. I'm not touching them with a 10 foot pole for the rest of the weekend though. We've had enough of their fun for one week.
@anurag_bhatia@captn3m0 The only place Iโve seen them in Canada is at hospitals. When you might be unexpectedly waiting in emergency 6-8 hours and forgot to bring your power bank with you. Somehow that happens to enough people to make it profitable
@anurag_bhatia I'd put big money on the return path being westbound via either TATA or NTT.
Unfortunately this has been a daily reality for months now due to very few undamaged cables still online between Japan and Singapore.
@anurag_bhatia In other words, the IP was definitely used for a Hong Kong GFE node at some point, but the PTR wasn't updated when they moved it to Mumbai.
@anurag_bhatia I used to see out of date PTRs for their GFE (Google Front End) nodes all the time back in the day, including double or even triple PTR records for the same IPs sometimes. This seems a lot rarer nowadays, but I suspect there's still a manual process somewhere.
@anurag_bhatia Nothing visible here, although we started seeing unusual worldwide ICMP-only drops since 20:40 UTC as well. Widespread across multiple networks, not just India.
UDP/TCP traffic is completely unaffected. Quite unusual. Might be a large-scale attack under way that we can't see.
@anurag_bhatia Something broke again at 17:29 UTC. Same thing as before; routes out of India via 9498 still present, but traffic blackholed before exiting 9498.
@anurag_bhatia Something that does seem to have changed in the past hour is that Airtel routes to Europe are now either via 4755 or via T1s in Singapore.
I wonder if they lost another big chunk of India <-> EU backbone.