I don't know of one, but doesn't mean there isn't one. Use something like fail2ban to search logs for these requests and ban the IP's automatically.
You can also work on implementing resource/quota limits to limit download requests, proxy/caching to mitigate the load, and alerts to notify you of when this is happening. Along with throttling our outgoing requests, because even if you weren't being DDoS'ed you don't want legit requests to overwhelm your available bandwidth.
Most vulnerabilities would be to "own" your server; crashing/ddos'ing it is counterproductive in that regard. The only reason to kill the server, really, is if someone has an axe to grind against your company.