Tadashi ยท Observed attack

TCP setup + UDP flood on OVH SAS in India

ยท Event #45

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Tadashi native vector 22: Attempts a TCP connection first, then repeatedly sends UDP payloads to the target port.

All TCP setup + UDP flood observations
Observed
2026-09-29T21:34:37.850Z
Recorded

Recorded 171m 53s after observation

Affected network
148.113.47.73/32
Network operator
OVH SASAS16276
Method
TCP setup + UDP floodVector 22
Protocol
tcp/udp
Destination port
9100
Configured datagram length
Payload 1400 B
Commanded duration
10s
Observed via
13.140.176.180

All controllers with retained sightings of this order. Older records may have incomplete source coverage.

Geolocation data
ipinfo-lite-mmdb ยท 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.