Cereal2 · Observed attack

AS262675 UDP flood on 190.111.131.0/24 | 2026-10-10 20:17:50Z

· Event #324578

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T20:17:50.219Z
Recorded

Recorded 143ms after observation

Affected network
190.111.131.0/24
Network operator
Solucao Network Provedor LtdaAS262675
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
000000003c 4a 44 d4 ee c9 93 f5<JD.....
00000008c5 13 bd 4a bd 93 b7 27...J...'
00000010ec 17 70 d7 ea 4b 43 96..p..KC.
000000181c 5d 22 19 3f 31 27 48.]".?1'H

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

34548ee7576b56ea11d35bf13cea06b6d5c520fcdeb391cadf6925459689c21a

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
3c4a44d4eec993f5c513bd4abd93b727ec1770d7ea4b43961c5d22193f312748

Original bytes (Base64)

M2M0YTQ0ZDRlZWM5OTNmNWM1MTNiZDRhYmQ5M2I3MjdlYzE3NzBkN2VhNGI0Mzk2MWM1ZDIyMTkzZjMxMjc0OA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.