Cereal2 · Observed attack

AS262503 UDP flood on 167.249.168.0/24 | 2026-10-11 00:33:51Z

· Event #324918

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-11T00:33:51.274Z
Recorded

Recorded 140ms after observation

Affected network
167.249.168.0/24
Network operator
WIKI TELECOMUNICACOES EIRELIAS262503
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000b5 c7 fe b2 9c 81 23 53......#S
000000080f d1 d4 9f d7 a6 b5 6d.......m
0000001087 45 73 a8 6a 91 7e 75.Es.j.~u
0000001823 ec 36 34 68 49 3a ad#.64hI:.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

674d67c147649d62a5cf3b116f43875c37385a2843c43e16fc79ffabb9132a94

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
b5c7feb29c8123530fd1d49fd7a6b56d874573a86a917e7523ec363468493aad

Original bytes (Base64)

YjVjN2ZlYjI5YzgxMjM1MzBmZDFkNDlmZDdhNmI1NmQ4NzQ1NzNhODZhOTE3ZTc1MjNlYzM2MzQ2ODQ5M2FhZA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.