cShell DDoS Bot Attack Case Targeting Linux SSH Server (screen and hping3)
ID: 77703338-a0c7-58eb-9018-4c89a0995437
STIX ID: report--77703338-a0c7-58eb-9018-4c89a0995437
Feed Name: ASEC
Threat Score
AhnLab ASEC describes cShell, a Go-based DDoS bot deployed to poorly managed Linux servers via SSH brute-force; it installs under /etc/de/cARM, ensures persistence with a systemd service file, and leverages Linux utilities (screen and hping3) to conduct SYN/ACK/PSH/UDP/Xmas/FIN floods. The report documents the C2/update workflow (including Pastebin-based update URLs), command formats, supported attack options, and provides IOCs (MD5s, download URLs and multiple IP addresses).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
