Cereal2 · Observed attack

AS264186 UDP flood on 138.94.194.0/23 | 2026-10-11 00:05:51Z

· Event #324882

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-11T00:05:51.151Z
Recorded

Recorded 653ms after observation

Affected network
138.94.194.0/23
Network operator
AGT NETAS264186
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000dc 25 1c df b3 d3 81 82.%......
00000008ed 9f 85 e4 93 5e 94 3d.....^.=
00000010fc 6f 29 5d c0 cf ce 3b.o)]...;
0000001877 df b5 3e ce 75 2e 26w..>.u.&

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

ec443fa36ad2a02cab8cc90676e70bd45cbcb82faef7544ac2705b93ae7e4994

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
dc251cdfb3d38182ed9f85e4935e943dfc6f295dc0cfce3b77dfb53ece752e26

Original bytes (Base64)

ZGMyNTFjZGZiM2QzODE4MmVkOWY4NWU0OTM1ZTk0M2RmYzZmMjk1ZGMwY2ZjZTNiNzdkZmI1M2VjZTc1MmUyNg==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.