Cereal2 · Observed attack

AS52571 UDP flood on 187.95.92.0/24 | 2026-10-10 17:05:29Z

· Event #324333

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T17:05:29.964Z
Recorded

Recorded 142ms after observation

Affected network
187.95.92.0/24
Network operator
G2G COM PROD ELETRO E SERV LTDAAS52571
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
000000007b 86 4e d8 7e c3 b2 1b{.N.~...
000000086f 39 99 66 2a 74 dc 91o9.f*t..
000000104f 9d 77 c1 79 c6 44 6bO.w.y.Dk
00000018ed 1d a0 f1 6f ed f5 6c....o..l

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

dca40a842ad8a17e2fbe40db94afcd123b9ec3bec548549f46f1513cff3dd86b

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
7b864ed87ec3b21b6f3999662a74dc914f9d77c179c6446bed1da0f16fedf56c

Original bytes (Base64)

N2I4NjRlZDg3ZWMzYjIxYjZmMzk5OTY2MmE3NGRjOTE0ZjlkNzdjMTc5YzY0NDZiZWQxZGEwZjE2ZmVkZjU2Yw==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.