GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
2026-03-21T13:23:44Z•4e07977e599306de92ca873d016e823e8055844e391fab9a57c57227931de641
adminerbackdoorbashcowriegsockethoneypotioctag:ip:64.89.161.198ipv4-mapped-ipv6iranbotmalicious-scriptphpmyadminproxyscanningtelnet
What happened
Multiple ISC diary entries (Mar 16–20, 2026) report active scanning and malware activity observed in honeypots. Key items: a malicious Bash script was found that installs a GSocket backdoor on victim hosts (delivery vector and origin unknown). Cowrie honeypot logs captured a distinctive payload string (“MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here”), plus scanning activity, a successful Telnet login and related web/iptables activity from IP 64.89.161.198 (observed 30 Jan–22 Feb 2026). Honeypots also show broad scanning for admin interfaces (phpMyAdmin and Adminer) and attempts to探
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 4e07977e599306de92ca873d016e823e8055844e391fab9a57c57227931de641
- Enrichment time
- 2026-03-21T13:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.