same here, the type and extension of the attack make me thinking of a simple robot used by some guy connected to an ISP..VisualRoute also reports some other infos
inetnum: 218.86.128.0 - 218.86.255.255
netname: CHINANET-GZ
descr: CHINANET Guizhou province network
descr: Data Communication Division
descr: China Telecom
country: CN
admin-c: CH93-AP
tech-c: DL72-AP
mnt-by: MAINT-CHINANET
mnt-lower: MAINT-CHINANET-GZ
status: ASSIGNED NON-PORTABLE
changed:
[email protected] 20020424
changed:
[email protected] 20040927
source: APNIC
so banning a single class is meaningless, better would be to ban the whole provider..try looking at the contact's log in the china area of the forum instead..if a there's a log..