Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, 2026-09-08/09 (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 2743 sources in 1270 networks and 136 countries in the same period, the majority of which flooded udp/47472 where no service listens at all. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
DDoS AttackExploited Host
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.