Cereal2 · Observed attack

AS263614 UDP flood on 168.232.220.0/24 | 2026-10-10 18:35:30Z

· Event #324442

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T18:35:30.394Z
Recorded

Recorded 152ms after observation

Affected network
168.232.220.0/24
Network operator
RVA TELECOM LTDAAS263614
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000013 92 92 f6 07 88 e1 1a........
0000000837 f6 a0 cf 17 2e c5 f27.......
00000010bd 30 c3 8e aa 3f d6 35.0...?.5
000000181f 92 0f f2 2c 3b 6a 0e....,;j.

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

112804e9c0007c3dc8d9d63f36566b04b36291c89e15f42174d8586c85f3ff8c

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
139292f60788e11a37f6a0cf172ec5f2bd30c38eaa3fd6351f920ff22c3b6a0e

Original bytes (Base64)

MTM5MjkyZjYwNzg4ZTExYTM3ZjZhMGNmMTcyZWM1ZjJiZDMwYzM4ZWFhM2ZkNjM1MWY5MjBmZjIyYzNiNmEwZQ==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.