ISC Stormcast For Thursday, March 19th, 2026 https://isc.sans.edu/podcastdetail/9856, (Thu, Mar 19th)

2026-03-20T01:23:44Z0599e823c6b661197300c0e9913d86e2ff205ec6822dda4ce23f728f9a22ede6
ClickFixEmailJSRATRemcosSmartApeSGadminercowriecredential-theftdshieldhoneypotiptablesipv4-mapped-ipv6iranbotphishingphpmyadminportscanproxy-scansreacttelnetwebhoneypot

What happened

SANS ISC diary collection (Mar 13–19, 2026) summarizing multiple observed threats and telemetry from honeypots/DShield sensors: (1) Cowrie honeypot logs show an echo containing a banner-like string (“MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here”) and activity (port scans, successful Telnet login) from IP 64.89.161.198; (2) widespread scanning for web admin interfaces, including probes for phpMyAdmin and Adminer; (3) many proxy/"/proxy/" URL scans and use of IPv4-mapped IPv6 addresses to potentially obfuscate origin; (4) a SmartApeSG campaign delivering the Remcos RAT via a ClickF‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
0599e823c6b661197300c0e9913d86e2ff205ec6822dda4ce23f728f9a22ede6
Enrichment time
2026-03-20T01:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Thursday, March 19th, 2026 https://isc.sans.edu/podcastdetail/9856, (Thu, Mar 19th) · Baitaphish