Cereal2 · Observed attack

AS263650 UDP flood on 138.255.150.0/24 | 2026-10-10 20:15:50Z

· Event #324575

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T20:15:50.206Z
Recorded

Recorded 142ms after observation

Affected network
138.255.150.0/24
Network operator
Clicfacil TelecomAS263650
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000f9 aa d5 19 1c 1b 09 63.......c
00000008ff 0d 7b 82 63 15 d0 c1..{.c...
0000001059 c6 8d 9c 39 42 eb 32Y...9B.2
00000018ec fd 12 fb ea 88 cc 60.......`

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

b718d6bc807a3e5a8474aae042b4ceee4b6e677a616453f67e5c28f5e98faf1e

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
f9aad5191c1b0963ff0d7b826315d0c159c68d9c3942eb32ecfd12fbea88cc60

Original bytes (Base64)

ZjlhYWQ1MTkxYzFiMDk2M2ZmMGQ3YjgyNjMxNWQwYzE1OWM2OGQ5YzM5NDJlYjMyZWNmZDEyZmJlYTg4Y2M2MA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.