Cereal2 · Observed attack

AS262675 UDP flood on 190.111.131.0/24 | 2026-10-10 18:33:30Z

· Event #324440

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:33:30.302Z
Recorded

Recorded 161ms after observation

Affected network
190.111.131.0/24
Network operator
Solucao Network Provedor LtdaAS262675
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
000000009d ee 08 c4 e1 79 af e1.....y..
0000000833 7a 96 a4 1c 81 de eb3z......
0000001038 35 52 ab f2 89 64 7385R...ds
0000001808 72 6e 82 a1 95 2d af.rn...-.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

7b9fc064f4d044c067e221fa7705e0c07761dd2da43c3b886857a937778145dc

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
9dee08c4e179afe1337a96a41c81deeb383552abf289647308726e82a1952daf

Original bytes (Base64)

OWRlZTA4YzRlMTc5YWZlMTMzN2E5NmE0MWM4MWRlZWIzODM1NTJhYmYyODk2NDczMDg3MjZlODJhMTk1MmRhZg==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.