Cereal2 · Observed attack

AS263614 UDP flood on 168.232.221.0/24 | 2026-10-10 18:37:30Z

· Event #324444

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:37:30.371Z
Recorded

Recorded 157ms after observation

Affected network
168.232.221.0/24
Network operator
RVA TELECOM LTDAAS263614
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000041 9e e9 f7 37 c0 66 50A...7.fP
000000085f c8 72 14 10 d4 e6 46_.r....F
0000001073 21 68 05 67 9e 64 14s!h.g.d.
0000001884 d5 a4 da ed 32 d1 cb.....2..

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

48fd54de6f4fd2bddd2faaaa80e19cc0e93042eae1e9365c948944248d69ac45

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
419ee9f737c066505fc8721410d4e64673216805679e641484d5a4daed32d1cb

Original bytes (Base64)

NDE5ZWU5ZjczN2MwNjY1MDVmYzg3MjE0MTBkNGU2NDY3MzIxNjgwNTY3OWU2NDE0ODRkNWE0ZGFlZDMyZDFjYg==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.