Loading...
KSI Digital
PerlBot Dred: finding the missing C2 of an IRC DDoS bot
Threat Research

PerlBot Dred: finding the missing C2 of an IRC DDoS bot

A Perl IRC flood bot landed in our SSH honeypot. The sample was already known, but the IRC server that controls it was not on public feeds. We read it from the sample's configuration and reported it.

KSI Digital Solutions
2026-10-05
5 min

Not every finding is a new malware family. Often the useful contribution is filling a gap in what is already known. On 3 October 2026 a Perl-based bot was dropped on our SSH honeypot. The sample and the URL it was downloaded from were already on public feeds, credited to their original reporters. The IRC server that controls the bot, its command-and-control (C2) server, was not. We identified it from the sample's own configuration and reported it, so that others can block it too.

For an organisation running Linux servers, the lesson is a familiar one. In this case, an SSH login as root was all the actor needed to turn a server into a participant in someone else's denial-of-service (DDoS) attacks.

How it reached our honeypot

Between 09:47 and 09:53 UTC on 3 October 2026, an actor logged in to our Cowrie SSH honeypot as root and ran the same short command line nine times. Each run printed system information, listed graphics adapters, downloaded a Perl script named dred from 192.227.210[.]190 into /tmp, and ran it with Perl.

The download server is hosted at ColoCrossing and has been listed on URLhaus since 21 September 2026.

What the analysis showed

We analysed the script statically, by reading its code and configuration. We did not join the IRC server.

What it is. The 44,755-byte script calls itself "DDoS Perl IrcBot v2.0". It is a rebrand of PBot, a public Perl bot from the Romanian scene; its greeting string, Pregatit de actiune!, gives away that origin. The operator's nickname is Dred.

How it is controlled. The bot connects to an IRC server at 23.95.235[.]108 on port 6667, joins the channel #new and takes commands from the admin nick Dred. That server is hosted at ColoCrossing, sub-allocated to a provider called "VPS ACE". The sample also carries the string dreds[.]network together with an UnrealIRCd host cloak. That domain is not registered (it returns NXDOMAIN), so it is an IRC cloak rather than a domain anyone can resolve or block.

How it behaves. The bot forks into the background, renames its own process, ignores the usual interrupt and termination signals (INT, HUP, TERM) and works from /tmp. It has no persistence, so it does not survive a reboot.

What it can do. On command it can run UDP, TCP, HTTP and IRC floods, scan ports, open a reverse shell, download files, send spam mail and run arbitrary shell commands. In short, a server running it becomes both a source of DDoS traffic against third parties and a remote shell for the operator.

What defenders can do

  • Harden SSH first. This bot arrived through a root login. Disable password logins for root, prefer key-based authentication, and limit who can reach SSH.

  • Block outbound IRC from servers. Outbound TCP to ports 6667 or 6697 from a server that has no business on IRC is a useful signal, and easy to block at the firewall.

  • Watch for the process pattern. A Perl process running from /tmp, with a renamed process name, started right after a curl download of a file called dred.

  • Search for its strings. The literal strings Pregatit de actiune! or DDoS Perl IrcBot in files or memory point to this bot or its PBot relatives.

  • Reboot, then fix the cause. Because the bot has no persistence, a reboot stops it, but the login it came in through remains open until credentials and SSH settings are fixed.

  • Use the published rules. Our repository has YARA and Suricata rules for the signals above.

Key indicators

IndicatorRoleReference
23.95.235[.]108:6667IRC C2 server (channel #new)ThreatFox 1948443
hxxp://192.227.210[.]190/dredDownload URLURLhaus 3920026
a37649842a47b845...Sample "DDoS Perl IrcBot v2.0", 44,755 bytes (SHA-256 prefix)on MalwareBazaar
Pregatit de actiune!PBot-derived greeting stringiocs.csv
dreds[.]networkIRC host cloak (NXDOMAIN, not a resolvable domain)iocs.csv

The indicators are also in machine-readable form in the finding's iocs.csv, with the full technical write-up alongside.

How we work

KSI Digital runs a WordPress bait and a Cowrie SSH/Telnet honeypot that record attacks and keep the files attackers download. We analyse samples offline in an isolated lab and never connect to attacker infrastructure outside it. Here the C2 came from the sample's configuration alone. Before we report an indicator, we check it against existing feeds, so we add what is missing rather than duplicating what others have already shared. More on our research page and in our methodology.


Indicators shared with ThreatFox, URLhaus and AbuseIPDB as ksi_digital. For this finding we reported the IRC C2 to ThreatFox (ID 1948443); the sample and download URL were already on MalwareBazaar and URLhaus, credited to their original reporters. Corrections are welcome: open an issue on GitHub or email christophe@ksi-digital.com.

Tags

Threat ResearchCybersecurityBotnetDDoSLinuxHoneypot

Concerned about these threats?

We test and monitor Indonesian organisations against the attacks our sensors see every day.

Our cybersecurity services