Cereal2 · Observed attack

AS22356 UDP flood on 177.190.108.0/24 | 2026-10-10 17:33:30Z

· Event #324364

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T17:33:30.122Z
Recorded

Recorded 140ms after observation

Affected network
177.190.108.0/24
Network operator
Durand do Brasil LtdaAS22356
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000c0 95 e4 51 14 e0 b7 51...Q...Q
00000008ec 3c e3 7e 64 75 1c 88.<.~du..
00000010db 79 89 78 d2 2b a2 e4.y.x.+..
0000001892 84 24 42 ec be db d4..$B....

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

6ceab1ad17b857a2f84440be92ef38a0cf0f436dc14dda6985719a3982e9f249

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
c095e45114e0b751ec3ce37e64751c88db798978d22ba2e492842442ecbedbd4

Original bytes (Base64)

YzA5NWU0NTExNGUwYjc1MWVjM2NlMzdlNjQ3NTFjODhkYjc5ODk3OGQyMmJhMmU0OTI4NDI0NDJlY2JlZGJkNA==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.