EZF3 · Observed attack

Raw TCP packet flood on KPN B.V. in Netherlands

· Event #6

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

EZF3 vector 4 constructs and sends raw IPv4/TCP packets. Specific TCP flag combinations are not assigned a marketing label.

All Raw TCP packet flood observations
Observed
2026-09-27T16:30:25.447Z
Recorded

Recorded 288ms after observation

Affected network
77.171.28.225/32
Network operator
KPN B.V.AS1136
Method
Raw TCP packet floodVector 4
Protocol
tcp
Destination port
53
Commanded duration
20s
Observed via
176.53.159.21

All controllers with retained sightings of this order. Older records may have incomplete source coverage.

Geolocation data
ipinfo-lite · 2026-07

Snapshot taken at ingestion; it is never re-resolved later.

Other attacks on this network

Within 24 hours of this observation

No other observations within 24 hours.

Other attacks in this country

Within 24 hours of this observation

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.