Analysis of Attacks That Install Scanners on Linux SSH Servers
ID: c4dfc8f2-219b-5522-98f4-5d7e228c93d2
STIX ID: report--c4dfc8f2-219b-5522-98f4-5d7e228c93d2
Feed Name: ASEC
**Executive summary:** AhnLab ASEC documents an active campaign that scans for Linux SSH (port 22), uses dictionary/brute-force attacks to harvest credentials, and installs port scanners, SSH brute-force tools and potentially DDoS bots or XMRig coinminers; the report details the attack flow, toolset (e.g., go, gob, prg, ps), IOCs (attacker IPs, URL http://58.216.207.82/scan.tar, MD5s), historical linkage to tools from the PRG old Team, and mitigation guidance (strong passwords, patching, firewalls, AV updates).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
