Cereal2 · Observed attack

AS263614 UDP flood on 177.23.109.0/24 | 2026-10-10 18:45:30Z

· Event #324456

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:45:30.402Z
Recorded

Recorded 147ms after observation

Affected network
177.23.109.0/24
Network operator
RVA TELECOM LTDAAS263614
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000fd e9 aa eb 54 48 45 47....THEG
00000008e5 9b 97 a0 a3 37 83 63.....7.c
0000001006 0a 1c a2 de b7 b7 4c.......L
0000001845 96 4c b6 21 c7 e0 c2E.L.!...

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

a6d574303084c9099e69e2bd1eba1180f2241ebf267fb3fcb39e870b9aa3e9c9

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
fde9aaeb54484547e59b97a0a3378363060a1ca2deb7b74c45964cb621c7e0c2

Original bytes (Base64)

ZmRlOWFhZWI1NDQ4NDU0N2U1OWI5N2EwYTMzNzgzNjMwNjBhMWNhMmRlYjdiNzRjNDU5NjRjYjYyMWM3ZTBjMg==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.