Cereal2 · Observed attack

AS269033 UDP flood on 45.177.85.0/24 | 2026-10-11 21:24:05Z

· Event #326287

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-11T21:24:05.702Z
Recorded

Recorded 380ms after observation

Affected network
45.177.85.0/24
Network operator
Extremnet TelecomAS269033
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
000000008a 69 99 3e ff c2 32 49.i.>..2I
0000000811 18 7b 6e 34 4b c0 0d..{n4K..
0000001019 82 b8 1f 9e 38 a7 fa.....8..
0000001870 7a 35 72 03 9b 67 2epz5r..g.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

11469fd04a6e8e140aeb72ad8fa465283bfe249f07395b5d637c73224b7d6380

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
8a69993effc2324911187b6e344bc00d1982b81f9e38a7fa707a3572039b672e

Original bytes (Base64)

OGE2OTk5M2VmZmMyMzI0OTExMTg3YjZlMzQ0YmMwMGQxOTgyYjgxZjllMzhhN2ZhNzA3YTM1NzIwMzliNjcyZQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.