Cereal2 · Observed attack

AS61855 UDP flood on 131.0.7.0/24 | 2026-10-10 23:43:51Z

· Event #324852

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T23:43:51.057Z
Recorded

Recorded 138ms after observation

Affected network
131.0.7.0/24
Network operator
NOVA NET TECNOLOGIA LTDA - MEAS61855
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000be d4 a4 09 ab 53 e5 a0.....S..
000000081e a6 86 e7 f1 27 7d e0.....'}.
0000001062 f9 1c 5a d1 c3 21 4bb..Z..!K
0000001887 3a be 3d 8a 88 9c 76.:.=...v

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

f98c4325f0c033ff1b90cb62658983d73d782463de8bf4769d5a53f916fff1cd

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
bed4a409ab53e5a01ea686e7f1277de062f91c5ad1c3214b873abe3d8a889c76

Original bytes (Base64)

YmVkNGE0MDlhYjUzZTVhMDFlYTY4NmU3ZjEyNzdkZTA2MmY5MWM1YWQxYzMyMTRiODczYWJlM2Q4YTg4OWM3Ng==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.