Cereal2 ยท Observed attack

AS138995 TCP flood on 108.187.9.173 | 2026-09-18 04:58:46Z

ยท Event #234977

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 9: Nonblocking TCP connection and session-pool flood.

All Nonblocking TCP connection and session-pool flood observations
Observed
2026-09-18T04:58:46.885Z
Recorded

Recorded 547ms after observation

Affected network
108.187.9.173/32
Network operator
Antbox Networks LimitedAS138995
Method
Nonblocking TCP connection and session-pool floodVector 9
Protocol
tcp
Destination port
80
Commanded duration
1m
Geolocation data
ipinfo-lite ยท 2026-07

Snapshot taken at ingestion; it is never re-resolved later.

Other attacks on this network

Within 24 hours of this observation

Other attacks in this country

Within 24 hours of this observation

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.