Cereal2 · Observed attack

AS264076 UDP flood on 143.202.184.0/24 | 2026-10-10 23:11:50Z

· Event #324803

WhatsApp

Country-level precision. botnet.cl stores the target country, never a city or coordinates, so the marker sits at the country's center.

What this method does

Cereal2 vector 19: Configurable custom-payload UDP flood.

All Configurable custom-payload UDP flood observations
Observed
2026-10-10T23:11:50.936Z
Recorded

Recorded 142ms after observation

Affected network
143.202.184.0/24
Network operator
BREM TECHNOLOGY LTDAAS264076
Method
Configurable custom-payload UDP floodVector 19
Protocol
udp
Destination port
Randomized
Commanded duration
1m
Geolocation data
ipinfo-lite · 2026-09

Snapshot taken at ingestion; it is never re-resolved later.

Payload observed in C2 command

Observed command data; this does not establish what reached the target.

Custom payload · 32 bytes

Decoded template · 32 bytes

OffsetHexadecimalASCII
0000000060 36 fa 4c a3 9e 99 16`6.L....
0000000844 15 5a ff d0 68 d1 8dD.Z..h..
00000010d3 e5 a0 84 f7 e3 3c c1......<.
0000001800 e6 69 d3 57 c1 a2 66..i.W..f

8 or 16 bytes per row, depending on screen width. Dots represent non-printable bytes.

SHA-256 of decoded template

d41617922f3a55b154bde647f00812e0ed764a8c11af71aa2f7a0944692eafd6

Configured datagram length
1400 bytes
Minimum length option
1000 bytes
Maximum length option
1400 bytes

Length options are command settings, not measured packet sizes. The decoded template can differ from the resulting datagrams.

Original encoded value
6036fa4ca39e991644155affd068d18dd3e5a084f7e33cc100e669d357c1a266

Original bytes (Base64)

NjAzNmZhNGNhMzllOTkxNjQ0MTU1YWZmZDA2OGQxOGRkM2U1YTA4NGY3ZTMzY2MxMDBlNjY5ZDM1N2MxYTI2Ng==

botnet.cl reports infrastructure it observed. An address appearing here identifies a target or a relay, not a person responsible for the attack.