Tadashi ยท Observed attack

TCP connection and payload flood on OVH SAS in India

ยท Event #43

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Tadashi native vector 17: Opens TCP connections and repeatedly sends payload data; an optional mode uses raw TCP packets.

All TCP connection and payload flood observations
Observed
2026-09-29T21:32:38.118Z
Recorded

Recorded 173m 52s after observation

Affected network
148.113.47.73/32
Network operator
OVH SASAS16276
Method
TCP connection and payload floodVector 17
Protocol
tcp
Destination port
9100
Commanded duration
10s
Observed via
13.140.176.180

All controllers with retained sightings of this order. Older records may have incomplete source coverage.

Geolocation data
ipinfo-lite-mmdb ยท 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.