Cereal2 · Observed attack

AS264323 UDP flood on 138.121.246.0/24 | 2026-10-10 17:27:30Z

· Event #324356

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T17:27:30.058Z
Recorded

Recorded 139ms after observation

Affected network
138.121.246.0/24
Network operator
OXMAN TECNOLOGIA LTDAAS264323
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
000000006b 22 7f 75 7f fc 78 a7k".u..x.
000000088e 82 f6 ca cd 92 06 27.......'
00000010df 88 2f 30 24 d8 6b 49../0$.kI
000000186e 9b 46 a4 b0 76 55 b0n.F..vU.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

1914b370e13bb96b8ef0e9c68b206f58ebdfda8b1d6069f4956ce5a63963039a

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
6b227f757ffc78a78e82f6cacd920627df882f3024d86b496e9b46a4b07655b0

Original bytes (Base64)

NmIyMjdmNzU3ZmZjNzhhNzhlODJmNmNhY2Q5MjA2MjdkZjg4MmYzMDI0ZDg2YjQ5NmU5YjQ2YTRiMDc2NTViMA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.