ShellBot, also known as PerlBot, is a Perl-based IRC botnet malware family used for distributed denial-of-service attacks and remote control of compromised Linux systems. It connects to IRC command-and-control servers, receives operator commands, and uses IRC PING/PONG exchanges to maintain connectivity. Its capabilities include system command execution, reverse-shell access, targeted and full-range port scanning, file downloads, data exfiltration, and UDP, TCP, and HTTP flooding. Some variants can retrieve and install additional malware.
ShellBot is deployed against internet-exposed servers through brute-force and dictionary attacks on weak SSH credentials and through exploitation of vulnerable web applications. Observed exploitation vectors include Cacti CVE-2022-46169, vBulletin CVE-2020-17496, and Bash Shellshock. Deployments have also followed compromise of a Tomcat container using default administrative credentials. Variants include LiGhT’s Modded perlbot v2, PowerBots, and B0tchZ.
ShellBot deployments can establish persistence through cron jobs, startup scripts, or shell configuration changes. Evasion measures include Perl obfuscation, masquerading as legitimate service processes, and deployment scripts that remove forensic traces. Some samples ignore termination-related signals to improve resilience. The Outlaw threat group has used ShellBot within Linux-focused botnet and cryptomining operations. Other campaigns have deployed it alongside Tsunami, XMRig, and log-cleaning tools; cryptocurrency mining in these deployments is performed by separate miner payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
FortiGuard Labs observed several attacking bursts targeting Cacti and Realtek vulnerabilities ... and then spreading ShellBot and Moobot malware. ... CVE-2021-35394 (Realtek) and CVE-2022-46169 (Cacti).
CVE-2022-46169 is a command injection vulnerability that allows an unauthenticated user to execute arbitrary code on a server running Cacti. The vulnerability resides in the “remote_agent.php” file, which can be accessed without authentication.
Recently, Unit 42 researchers found exploits in the wild leveraging the vBulletin pre-auth RCE vulnerability CVE-2020-17496. The exploits are a bypass of the fix for the previous vulnerability, CVE-2019-16759... We caught the first incident of CVE-2020-17496 exploitation on Aug. 10, 2020, and later found that exploitation attempts from different IP addresses are ongoing. | Some attackers are utilizing the vulnerability to download a Perl-based script malware (Shellbot) with the PHP function shell_exec() for the execution of the system command wget from the address http://178[.]170[.]117[.]50/bot1 and run it.
The exploitation of the BASH bug, now widely referred to as “Shellshock”, is in full swing... The initial patch for this vulnerability (CVE-2014-6271), which was released in sync with the vulnerability’s public disclosure, was quickly found to be inadequate. | The Perl script (md5: cd23ef54e264bd84ab1a12dddceb3f48) was first submitted to VirusTotal over a year ago and is known as ShellBot. It is an IRC bot with remote shell, scanning, and DDoS functionality.
This time, the group explored unpatched systems vulnerable to CVE-2016-8655 and Dirty COW exploit (CVE-2016-5195) as attack vectors.
This time, the group explored unpatched systems vulnerable to CVE-2016-8655 ... as attack vectors.
The Perl script (md5: cd23ef54e264bd84ab1a12dddceb3f48) was first submitted to VirusTotal over a year ago and is known as ShellBot. It is an IRC bot with remote shell, scanning, and DDoS functionality.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The a binary is a script wrapper to start run, a Perl-obfuscated script for installation of a Shellbot to gain control of the infected system. The Shellbot disguises itself as a process named rsync... Shellbot is also used to control the botnet...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
It then resets cron and removes possible cache files from other programs, starts scripts and binaries a, init0, and start, and sets the persistence by modifying the crontab.
The attacker gained access to the Tomcat container, brute forcing its default credentials and spawning a reverse shell. | These are the real Shellbot malware that forces the victim to communicate with the IRC server, executing and running whatever it wants.
These payloads try to execute system commands echo and id... The payload contains the PHP function shell_exec() for the execution of arbitrary system commands and a system command cat ../../../../../../../../../../etc/passwd...
The a binary is a script wrapper to start run, a Perl-obfuscated script for installation of a Shellbot to gain control of the infected system.
By exploiting this vulnerability, an attacker could have gained privileged access and control over any vBulletin server running versions 5.0.0 up to 5.5.4... allows attackers to send a crafted HTTP request with a specified template name and malicious PHP code, and leads to remote code execution.
It modified the shell configuration file so that it will download the files again when the user opens a new terminal.
It then resets cron and removes possible cache files from other programs, starts scripts and binaries a, init0, and start, and sets the persistence by modifying the crontab.
It modified the shell configuration file so that it will download the files again when the user opens a new terminal.
The Shellbot disguises itself as a process named rsync, commonly the binary seen on many Unix- and Linux-based systems to automatically run for backup and synchronization.
They also tracked down an IP address that had attempted to connect to the OSI server 38 times in what Air Force investigators called an SSH brute-force attack.
This ulimit.sh script initially checked the $EUID variable as a way to see if the attacker had root permissions.
It can also ask to perform a port scanning, which has the purpose to contact some specific ports of the target IP or a full-port scanning.
Bot.pl and craton.pl are two identical scripts used to communicate with different IRC servers, via different ports. | Shellbot malware enables the attackers to communicate with the C&C server... The C&C server, also called the IRC server in this scenario
Tsunami connects to the IRC server, joins a channel, and waits for the threat actor’s commands... ShellBot ... is also an IRC Bot that utilizes the IRC protocol like Tsunami.
Here is the PING-PONG exchange that is used to keep the communication channel alive between the bot and the IRC server.
On November 16, 2020, OSI said one of its engineers found a cryptominer on one of its servers during a routine maintenance operation. The crypto-mining malware, which was running at full capacity, had blocked the server altogether, which was failing to process valid requests.
121 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The Sysdig research team analyzes other malware, like serv-hello or Shellbot, with similar behavior.
IRC-controlled malware that establishes command-and-control communications, downloads and launches multiple binaries/scripts for different architectures, performs file download, port scanning, data exfiltration, persistence and cleanup, and can be used to conduct DDoS/flooding attacks from compromised systems.
Propagation-capable Linux malware used in the attacks to help distribute or install the XMRig CoinMiner on targeted servers.
Perl-based IRC bot used for DDoS and remote system control on infected Linux servers. In this campaign it was distributed alongside the coin miner tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.