This is what the change in activity looked like from the top 50 ISPs from where these attacks were originating during a 72 hour period ending yesterday (Monday) evening. As you can see, starting at around midnight on Sunday night (April 30th) Pacific time, the number of attacks we are seeing from ISPs where we found vulnerable routers have dropped from peaks of 40,000 in some cases to peaks of just above 5,000 attacks per hour.

In many cases the attacks drop to much lower levels and continue to decrease.

After a target IP is known the attacker proceeds to do a more detailed scan on the target (

By doing this, nmap shows what possible services (ports) the target has running and the version of the service and then attempts to identify the operating system (OS).

