Cereal2 · Observed attack

AS264323 UDP flood on 138.121.245.0/24 | 2026-10-10 17:25:30Z

· Event #324354

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T17:25:30.037Z
Recorded

Recorded 138ms after observation

Affected network
138.121.245.0/24
Network operator
OXMAN TECNOLOGIA LTDAAS264323
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000021 2b 67 ae 05 3c d9 cf!+g..<..
0000000885 64 98 03 45 41 c1 0b.d..EA..
000000101b cf 2e fc d5 e5 91 20.......
0000001871 8d 1d 50 14 93 1b 90q..P....

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

62654594092b802fc30186c232c4904b0be444b4d2485abfaef144d0ef107390

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
212b67ae053cd9cf856498034541c10b1bcf2efcd5e59120718d1d5014931b90

Original bytes (Base64)

MjEyYjY3YWUwNTNjZDljZjg1NjQ5ODAzNDU0MWMxMGIxYmNmMmVmY2Q1ZTU5MTIwNzE4ZDFkNTAxNDkzMWI5MA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.