GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)

2026-03-21T13:23:44Z4e07977e599306de92ca873d016e823e8055844e391fab9a57c57227931de641
adminerbackdoorbashcowriegsockethoneypotioctag:ip:64.89.161.198ipv4-mapped-ipv6iranbotmalicious-scriptphpmyadminproxyscanningtelnet

What happened

Multiple ISC diary entries (Mar 16–20, 2026) report active scanning and malware activity observed in honeypots. Key items: a malicious Bash script was found that installs a GSocket backdoor on victim hosts (delivery vector and origin unknown). Cowrie honeypot logs captured a distinctive payload string (“MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here”), plus scanning activity, a successful Telnet login and related web/iptables activity from IP 64.89.161.198 (observed 30 Jan–22 Feb 2026). Honeypots also show broad scanning for admin interfaces (phpMyAdmin and Adminer) and attempts to探

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4e07977e599306de92ca873d016e823e8055844e391fab9a57c57227931de641
Enrichment time
2026-03-21T13:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.