Cereal2 · Observed attack

AS28663 UDP flood on 177.93.238.0/24 | 2026-10-09 23:14:27Z

· Event #322004

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-09T23:14:27.813Z
Recorded

Recorded 164ms after observation

Affected network
177.93.238.0/24
Network operator
FLYS INTERATIVA LTDAAS28663
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000ee 87 64 b5 bb 93 21 e2..d...!.
0000000848 c8 32 4f e6 84 19 a7H.2O....
000000101d aa dd b3 5f 12 5f fd...._._.
0000001874 71 d4 cc f7 ef 58 2dtq....X-

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

20adef5df018bca2d9d1f5c960ddba7a5acf73dbb28df5fec4c8215d646b3d88

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
ee8764b5bb9321e248c8324fe68419a71daaddb35f125ffd7471d4ccf7ef582d

Original bytes (Base64)

ZWU4NzY0YjViYjkzMjFlMjQ4YzgzMjRmZTY4NDE5YTcxZGFhZGRiMzVmMTI1ZmZkNzQ3MWQ0Y2NmN2VmNTgyZA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.