Cereal2 · Observed attack

AS263539 UDP flood on 191.5.174.0/24 | 2026-10-10 18:31:30Z

· Event #324438

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:31:30.289Z
Recorded

Recorded 378ms after observation

Affected network
191.5.174.0/24
Network operator
NEW SYSTEM INTERNETAS263539
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000064 ee 85 42 02 bf df 9fd..B....
000000082c 75 0b bf 79 11 ff 02,u..y...
000000109f 72 69 e9 68 47 b7 f7.ri.hG..
0000001843 ec 26 7a 58 06 34 31C.&zX.41

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

112a693380b4a97d6677befb138640effde4a2c38ee4749a3184129c6767e12f

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
64ee854202bfdf9f2c750bbf7911ff029f7269e96847b7f743ec267a58063431

Original bytes (Base64)

NjRlZTg1NDIwMmJmZGY5ZjJjNzUwYmJmNzkxMWZmMDI5ZjcyNjllOTY4NDdiN2Y3NDNlYzI2N2E1ODA2MzQzMQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.