It looks like it's hosted in the US (ec2-184-72-37-90.us-west-1.compute.amazonaws.com). Also, the front end proxy is doing some heavy filtering to weed out the cheap hit-and-run nodes participating in the DDoS but still accepts legitimate browser-based requests (persistent). Notice how a Reset (R) is sent right away on the first try: 08:57:41.211436 IP managed.unixy.net.49467 > ec2-184-72-37-90.us-west-1.compute.amaz…
EC2 and Cloudfront are powerful technologies, here's hoping they're transparent and publish their solutions/tools.