New worm?

Don't know yet, as the support staff gone for the day at this time.


do you atleast have info about the packet
types/destinations/anything-useful ?

Netflow is showing a lot of 1500 byte packets, but many different destinations. It looks similar to gnutella traffic. Maybe just a lot files to share and our rate shapers are broken.

probably also it says ports and protocol?

New filesharing protocol?