EZF3 · Observed attack

UDP template flood on Hetzner Online GmbH in Germany

· Event #2

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

EZF3 vector 2 sends UDP payloads selected from a bank of service-query templates, including DNS and SSDP. Template presence alone does not establish a working reflection attack.

All UDP template flood observations
Observed
2026-09-27T12:08:11.984Z
Recorded

Recorded 159m 46s after observation

Affected network
88.99.164.31/32
Network operator
Hetzner Online GmbHAS24940
Method
UDP template floodVector 2
Protocol
udp
Destination port
53
Commanded duration
12s
Observed via
176.53.159.21

All controllers with retained sightings of this order. Older records may have incomplete source coverage.

Geolocation data
ipinfo-lite · 2026-07

Snapshot taken at ingestion; it is never re-resolved later.

Other attacks on this network

Within 24 hours of this observation

Other attacks in this country

Within 24 hours of this observation

No other observations within 24 hours.

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.