Cereal2 · Observed attack

AS22356 UDP flood on 177.190.111.0/24 | 2026-10-10 17:39:30Z

· Event #324370

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T17:39:30.106Z
Recorded

Recorded 371ms after observation

Affected network
177.190.111.0/24
Network operator
Durand do Brasil LtdaAS22356
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000a1 01 c2 69 14 23 58 98...i.#X.
00000008f2 6b d0 83 86 9d f8 b6.k......
0000001069 11 90 4f 25 b7 2e edi..O%...
00000018ae 8c e6 2c 5c bc ba af...,\...

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

d584035eecb18167354cbcd12725fe365891bc0f9e0870cc9f6eaffdcef73af5

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
a101c26914235898f26bd083869df8b66911904f25b72eedae8ce62c5cbcbaaf

Original bytes (Base64)

YTEwMWMyNjkxNDIzNTg5OGYyNmJkMDgzODY5ZGY4YjY2OTExOTA0ZjI1YjcyZWVkYWU4Y2U2MmM1Y2JjYmFhZg==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.