Looks to me like a SYN-ACK reflection attack, an inefficient form of DDOS. Some recent analysis of such attacks from Akamai can be found here.

Like most DDOS attacks this requires upstream support to mitigate. If only network operators would prevent spoofed IP source packets from egressing their network life would be much easier.