Cereal2 · Observed attack

AS264076 UDP flood on 143.202.185.0/24 | 2026-10-10 23:13:50Z

· Event #324807

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T23:13:50.945Z
Recorded

Recorded 139ms after observation

Affected network
143.202.185.0/24
Network operator
BREM TECHNOLOGY LTDAAS264076
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000dc 9d 76 eb b1 15 55 45..v...UE
00000008bf ca 66 da da 41 70 af..f..Ap.
0000001067 81 f8 fb b8 93 0c c9g.......
0000001816 ef 1e a0 5b a3 23 f5....[.#.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

1f0ef5ad72b684fc9122eeb35737b79189aade35bc131b3694f185ba3f0a268e

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
dc9d76ebb1155545bfca66dada4170af6781f8fbb8930cc916ef1ea05ba323f5

Original bytes (Base64)

ZGM5ZDc2ZWJiMTE1NTU0NWJmY2E2NmRhZGE0MTcwYWY2NzgxZjhmYmI4OTMwY2M5MTZlZjFlYTA1YmEzMjNmNQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.