Cereal2 · Observed attack

AS263614 UDP flood on 168.232.222.0/24 | 2026-10-10 18:39:30Z

· Event #324447

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:39:30.379Z
Recorded

Recorded 141ms after observation

Affected network
168.232.222.0/24
Network operator
RVA TELECOM LTDAAS263614
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
00000000a8 8a b5 bd 77 2a 18 bf....w*..
0000000836 67 38 5b da 0b 6f e06g8[..o.
0000001039 14 ef 79 0f 9e 44 849..y..D.
000000189f 0f 8f 87 42 5c 3f 0e....B\?.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

12809d114753e5aa616db11ff40fb481834a40477288d18599973b242714ae40

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
a88ab5bd772a18bf3667385bda0b6fe03914ef790f9e44849f0f8f87425c3f0e

Original bytes (Base64)

YTg4YWI1YmQ3NzJhMThiZjM2NjczODViZGEwYjZmZTAzOTE0ZWY3OTBmOWU0NDg0OWYwZjhmODc0MjVjM2YwZQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.