Cereal2 · Observed attack

AS264186 UDP flood on 138.94.192.0/23 | 2026-10-11 00:03:51Z

· Event #324880

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-11T00:03:51.143Z
Recorded

Recorded 139ms after observation

Affected network
138.94.192.0/23
Network operator
AGT NETAS264186
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000e8 f2 7b 91 37 22 ad 34..{.7".4
000000084c 2d 7b e7 8d 34 25 10L-{..4%.
0000001019 39 26 e0 c2 c1 40 24.9&...@$
00000018e2 b3 e0 d2 02 ef fe 4a.......J

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

26c5705eb1f8acb857921334d2336e1ace5893ab8b1ad81fbe487476df6c69d1

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
e8f27b913722ad344c2d7be78d342510193926e0c2c14024e2b3e0d202effe4a

Original bytes (Base64)

ZThmMjdiOTEzNzIyYWQzNDRjMmQ3YmU3OGQzNDI1MTAxOTM5MjZlMGMyYzE0MDI0ZTJiM2UwZDIwMmVmZmU0YQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.