Cereal2 · Observed attack

AS28146 UDP flood on 186.236.14.0/24 | 2026-10-10 18:05:30Z

· Event #324402

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:05:30.199Z
Recorded

Recorded 156ms after observation

Affected network
186.236.14.0/24
Network operator
MHNET TELECOMAS28146
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000026 0a ae c7 e1 c5 a5 ad&.......
00000008fc 79 c6 a5 9a 2e 47 f8.y....G.
000000102e 01 bb 03 03 3c 0e 70.....<.p
00000018a6 7c c4 27 d3 da 08 90.|.'....

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

b9a649d2c3ca796299f12b176a63474ad9e24cc744289f442e0cb77922d21c7a

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
260aaec7e1c5a5adfc79c6a59a2e47f82e01bb03033c0e70a67cc427d3da0890

Original bytes (Base64)

MjYwYWFlYzdlMWM1YTVhZGZjNzljNmE1OWEyZTQ3ZjgyZTAxYmIwMzAzM2MwZTcwYTY3Y2M0MjdkM2RhMDg5MA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.