botnet.cl route feed

BGP blackhole feed

Subscribe to individual C2 addresses as IPv4 /32 routes. Every route carries the well-known BLACKHOLE community plus source, threat, recency, and optional botnet-family metadata for local policy decisions.

Session details

BGP endpointChile
rbl1.botnet.cl

38.7.199.217A + AAAA DNS

BGP endpointSão Paulo, BR
rbl2.botnet.cl

45.171.231.57A + AAAA DNS

Remote AS
64512

Private ASN

Session type
Multihop

eBGP

Direction
Connect only

You initiate the session

Recommended: establish BGP sessions with both endpoints for path redundancy.Both hostnames publish A and AAAA records. The BGP services currently accept IPv4 sessions, use AS64512, and serve the same IPv4 /32 feed.

Informative communities

Community
65535:666
BLACKHOLE

Well-known RFC 7999 signal. Use this community to install the discard route.

64512:1001
C2

Classifies the announced address as command-and-control infrastructure.

64512:2001
botnet.cl

Identifies botnet.cl as the intelligence source, across all botnet families.

64512:3001
Seen <24 hours

The C2 address was observed less than 24 hours ago.

64512:3003
Seen >7 days

The C2 address was last observed more than seven days ago.

64512:4001
Cereal2

Labels C2 routes belonging to Cereal2. Use this community to select the Cereal2 family.

64512:4002
Aisuru-DDoS

Labels C2 routes belonging to the Aisuru-DDoS variant. Use this community to select that family.

64512:4003
Aisuru-Proxy

Labels C2 routes belonging to the Aisuru-Proxy variant. Use this community to select that family.

64512:4004
Potassium

Labels C2 routes belonging to Potassium. Use this community to select the Potassium family.

64512:4005
EZF3

Labels EZF3 C2 routes confirmed by authenticated commands. Use this community to select the EZF3 family.

64512:4006
Ouroboros

Labels Ouroboros C2 routes confirmed by recognized plaintext commands. Use this community to select the Ouroboros family.

64512:4007
Tadashi

Labels Tadashi C2 routes confirmed by authenticated inbound frames. Use this community to select the Tadashi family.

All seven families share source community 64512:2001. Use 64512:4001, 64512:4002, 64512:4003, 64512:4004, 64512:4005, 64512:4006, or 64512:4007 to select a botnet family. An IP shared by multiple families carries all matching family communities. The discard signal remains 65535:666.

Routes last seen from 24 hours through seven days ago have no age community. Exact 24-hour and seven-day boundaries are also unmarked.

What you receive

Export-only threat routes

botnet.cl announces one IPv4 /32 per listed C2 address. The AS_PATH includes AS64512 followed by the address origin ASN recorded by botnet.cl. The feed does not import subscriber routes.

Policy boundary

Only 65535:666 is required for the discard action. All 64512:* communities are informative and may be used for observability or more selective local policy.

Router installation

Choose your router vendor to get a guarded, connect-only BGP setup for the botnet.cl blackhole feed.

3 supported vendors

MikroTik

RouterOS v7

Community-based discard routing

The template opens separate connect-only sessions to rbl1.botnet.cl in Chile and rbl2.botnet.cl in São Paulo.

1

Install the input policy

Set the blackhole flag on routes carrying 65535:666, then reject every other route from this session.

/routing/filter/rule
add chain=cereal2-bgp-in rule="if (bgp-communities includes 65535:666) { set blackhole yes; accept; }"
add chain=cereal2-bgp-in rule="reject;"
2

Add the connect-only sessions

Create multihop eBGP connections to both feed servers and attach the input filter.

/routing/bgp/connection
add name=cereal2-rbl1 remote.address=38.7.199.217 \
    remote.as=64512 local.role=ebgp multihop=yes \
    connect=yes listen=no input.filter=cereal2-bgp-in
add name=cereal2-rbl2 remote.address=45.171.231.57 \
    remote.as=64512 local.role=ebgp multihop=yes \
    connect=yes listen=no input.filter=cereal2-bgp-in

Verify

Confirm both sessions are established, then inspect installed discard routes with /routing/route/print detail where blackhole. Keep the reject rule after the BLACKHOLE accept rule.