216.73.216.6

cShell DDoS Bot Attack Case Targeting Linux SSH Server (screen and hping3)

· Published 20/12/2024 14:22 · Modified 20/12/2024 14:41

Export JSON

Essential information

Published
20/12/2024 14:22
Modified
20/12/2024 14:41
Tags
2024-12-20 botnet brute-force carm cshell ddos go-language hping3 linux screen ssh
Related entities
1 observables, 12 techniques (mitre), 2 malware

Description

A new malware strain named is targeting poorly managed servers through services. The threat actor uses brute force attacks to gain initial access, then installs the bot developed in Go language. exploits tools '' and '' to perform various attacks. It supports multiple commands, including SYN, ACK, and UDP floods. The malware maintains persistence by registering as a service and can update itself using Pastebin URLs. 's simple design leverages existing tools, making it an effective bot. To protect against such attacks, administrators should use strong passwords, regularly update systems, and implement security measures like firewalls.

External references