Cereal2 · Observed attack

AS265465 UDP flood on 168.196.163.0/24 | 2026-10-10 23:45:51Z

· Event #324855

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T23:45:51.062Z
Recorded

Recorded 144ms after observation

Affected network
168.196.163.0/24
Network operator
JJVA Provedor de Internet ME LTDAAS265465
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
000000004e 2e fd b1 23 d4 91 05N...#...
0000000897 a1 f8 18 27 c6 1b 3b....'..;
000000100d 19 3c 52 41 ed 77 57..<RA.wW
0000001885 11 5a a1 af 2c ac ba..Z..,..

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

fa4f6202f9c4ad1a54eb0a414e033035ae2e2ddf45a47e97a18a146390be2a28

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
4e2efdb123d4910597a1f81827c61b3b0d193c5241ed775785115aa1af2cacba

Original bytes (Base64)

NGUyZWZkYjEyM2Q0OTEwNTk3YTFmODE4MjdjNjFiM2IwZDE5M2M1MjQxZWQ3NzU3ODUxMTVhYTFhZjJjYWNiYQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.