Cereal2 · Observed attack

AS28146 UDP flood on 186.236.13.0/24 | 2026-10-10 18:03:30Z

· Event #324398

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:03:30.198Z
Recorded

Recorded 155ms after observation

Affected network
186.236.13.0/24
Network operator
MHNET TELECOMAS28146
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
000000004e aa 6e 90 0c 6a 50 53N.n..jPS
0000000833 e6 dd 68 2a ce e0 6a3..h*..j
000000102a 69 f2 06 83 9c c2 ee*i......
0000001850 97 fa 6f a9 51 0d 1cP..o.Q..

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

7bd9642b900e10b00603b0f77c3c0b13ffbba1da87fe09b00d9f06aa3486a81f

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
4eaa6e900c6a505333e6dd682acee06a2a69f206839cc2ee5097fa6fa9510d1c

Original bytes (Base64)

NGVhYTZlOTAwYzZhNTA1MzMzZTZkZDY4MmFjZWUwNmEyYTY5ZjIwNjgzOWNjMmVlNTA5N2ZhNmZhOTUxMGQxYw==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.