One thing that pops to my mind is that we've seen a lot of TR-069/064 'SetNTPServers' exploits in the wild the past few days. Many of these try to download and execute a script, though some actually set the NTP servers first. Perhaps a huge number of devices that previously had no NTP configured, suddenly do?
Completely wild theory, but who knows.
Cam
-----Original Message-----
From: nznog-bounces(a)list.waikato.ac.nz [mailto:nznog-bounces(a)list.waikato.ac.nz] On Behalf Of Roland Dobbins
Sent: Friday, 16 December 2016 4:18 PM
To: nznog
We are also seeing the same sharp rise in NTP connections.
Maybe something like this?
http://pages.cs.wisc.edu/~plonka/netgear-sntp/
-----------------------------------
Roland Dobbins