You might want to check out the following write-ups from SANS:

http://isc.sans.org/diary.html?storyid=2038

http://isc.sans.org/diary.html?storyid=2040

There has been an upswing of these attacks.

Cheers: