Possible SYN flood DDoS attack from x47.c-style bot
This rule detects a potential SYN flood denial-of-service attack, characterized by a high volume of TCP SYN packets directed at a target within a short timeframe. Such activity is indicative of attempts to exhaust server resources by leaving TCP handshakes incomplete.
Suricata

