logo

cShell DDoS Bot Attack Case Targeting Linux SSH Server (screen and hping3)

ID: 77703338-a0c7-58eb-9018-4c89a0995437

STIX ID: report--77703338-a0c7-58eb-9018-4c89a0995437

Feed Name: ASEC

Threat Score
65/100

Date Published: 2024-12-10

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC describes cShell, a Go-based DDoS bot deployed to poorly managed Linux servers via SSH brute-force; it installs under /etc/de/cARM, ensures persistence with a systemd service file, and leverages Linux utilities (screen and hping3) to conduct SYN/ACK/PSH/UDP/Xmas/FIN floods. The report documents the C2/update workflow (including Pastebin-based update URLs), command formats, supported attack options, and provides IOCs (MD5s, download URLs and multiple IP addresses).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.