Cereal2 · Observed attack

AS28663 UDP flood on 177.93.238.0/24 | 2026-10-10 23:59:51Z

· Event #324875

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T23:59:51.117Z
Recorded

Recorded 156ms after observation

Affected network
177.93.238.0/24
Network operator
FLYS INTERATIVA LTDAAS28663
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000a8 db 9c 29 56 c6 b2 2d...)V..-
00000008ed 3d e1 d6 e1 02 6b 2f.=....k/
00000010ce 3e f6 da f2 c6 d5 c5.>......
0000001892 00 15 1d 06 c5 f5 e2........

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

10236d8c58ba83f4c60f4055bb58f210a25a2620d70d15c4eef3a6ccaf636cca

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
a8db9c2956c6b22ded3de1d6e1026b2fce3ef6daf2c6d5c59200151d06c5f5e2

Original bytes (Base64)

YThkYjljMjk1NmM2YjIyZGVkM2RlMWQ2ZTEwMjZiMmZjZTNlZjZkYWYyYzZkNWM1OTIwMDE1MWQwNmM1ZjVlMg==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.