Cereal2 · Observed attack

AS22356 UDP flood on 177.190.110.0/24 | 2026-10-10 17:37:30Z

· Event #324368

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T17:37:30.089Z
Recorded

Recorded 141ms after observation

Affected network
177.190.110.0/24
Network operator
Durand do Brasil LtdaAS22356
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000055 c9 03 87 82 5b 1c 72U....[.r
00000008b0 d1 88 ca 78 6c 75 90....xlu.
0000001067 3e 87 4c b6 05 ea 69g>.L...i
000000187d 3e 57 bc 71 f7 06 72}>W.q..r

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

231b7416d05c0be3962d2bf574bf8950facaf81ebf20c9b62fe2b93ae296eba1

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
55c90387825b1c72b0d188ca786c7590673e874cb605ea697d3e57bc71f70672

Original bytes (Base64)

NTVjOTAzODc4MjViMWM3MmIwZDE4OGNhNzg2Yzc1OTA2NzNlODc0Y2I2MDVlYTY5N2QzZTU3YmM3MWY3MDY3Mg==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.