Although we analyzed only two data sets of victim
logs, we can obtain some first, preliminary result. In both
attacks, several thousand infected machines sent concurrent
requests to the victim’s server and caused connectivity
problems with this flood of requests. We observe that
the country distribution is far from homogeneous in both
attacks. In fact, most bots related to the attack against VT
were based in Russia, while the attack against KOS was
mainly coming from South Asia (and being more evenly
distributed).