Cereal2 · Observed attack

AS263614 UDP flood on 177.23.111.0/24 | 2026-10-10 18:49:30Z

· Event #324462

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:49:30.382Z
Recorded

Recorded 146ms after observation

Affected network
177.23.111.0/24
Network operator
RVA TELECOM LTDAAS263614
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000020 f0 81 b1 63 0a a5 c4 ...c...
000000089b e2 56 90 f2 2f d5 71..V../.q
0000001071 ac e6 db 2e 4a 74 6dq....Jtm
00000018ec ad 69 d8 49 ec c4 d0..i.I...

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

8608816910638d7c05fed180912c141d8906277c1b1edb67ce30d9e0fcf5e3a0

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
20f081b1630aa5c49be25690f22fd57171ace6db2e4a746decad69d849ecc4d0

Original bytes (Base64)

MjBmMDgxYjE2MzBhYTVjNDliZTI1NjkwZjIyZmQ1NzE3MWFjZTZkYjJlNGE3NDZkZWNhZDY5ZDg0OWVjYzRkMA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.