EZF3 · Observed attack

HTTP request flood on Hetzner Online GmbH in Germany

· Event #3

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

EZF3 vector 12 builds HTTP requests with browser-style headers and sends them over TCP. Port 443 alone does not establish TLS.

All HTTP request flood observations
Observed
2026-09-27T13:27:43.866Z
Recorded

Recorded 80m 14s after observation

Affected network
138.201.139.144/32
Network operator
Hetzner Online GmbHAS24940
Method
HTTP request floodVector 12
Protocol
http
Destination port
80
Commanded duration
20s
Observed via
176.53.159.21

All controllers with retained sightings of this order. Older records may have incomplete source coverage.

Geolocation data
ipinfo-lite · 2026-07

Snapshot taken at ingestion; it is never re-resolved later.

Other attacks on this network

Within 24 hours of this observation

Other attacks in this country

Within 24 hours of this observation

No other observations within 24 hours.

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.