Cereal2 · Observed attack

AS53073 UDP flood on 187.87.45.0/24 | 2026-10-10 04:53:28Z

· Event #322995

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T04:53:28.650Z
Recorded

Recorded 148ms after observation

Affected network
187.87.45.0/24
Network operator
GD SERVIÇOS INTERNET LTDAAS53073
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000049 05 39 1f 21 6c 60 e5I.9.!l`.
000000086c b6 93 5c 8d 74 7b 4el..\.t{N
000000102a 62 2c 34 af b5 13 21*b,4...!
0000001877 3c 4a 9e 8a c5 71 few<J...q.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

bc1021702ad757c3ed4d08e9cb4ec375e5f56d84560e638456e3bdba47ba12ab

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
4905391f216c60e56cb6935c8d747b4e2a622c34afb51321773c4a9e8ac571fe

Original bytes (Base64)

NDkwNTM5MWYyMTZjNjBlNTZjYjY5MzVjOGQ3NDdiNGUyYTYyMmMzNGFmYjUxMzIxNzczYzRhOWU4YWM1NzFmZQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.