Cereal2 ยท Observed attack

Nonblocking TCP connection and session-pool flood on Antbox Networks Limited in Hong Kong

ยท Event #235019

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 9: Nonblocking TCP connection and session-pool flood.

All Nonblocking TCP connection and session-pool flood observations
Observed
2026-09-18T05:19:38.434Z
Recorded

Recorded 441ms after observation

Affected network
108.187.9.168/32
Network operator
Antbox Networks LimitedAS138995
Method
Nonblocking TCP connection and session-pool floodVector 9
Protocol
tcp
Destination port
80
Commanded duration
1m
Geolocation data
ipinfo-lite ยท 2026-07

Snapshot taken at ingestion; it is never re-resolved later.

Other attacks on this network

Within 24 hours of this observation

Other attacks in this country

Within 24 hours of this observation

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.