ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd)

2026-03-23T07:24:08Z72efc08a274f8ba86436dcf7696fefc0d3b861802a17f168113689f67bd95ca1
adminerbackdoorbashcowriegsockethoneypotip:64.89.161.198ipv4-mapped-ipv6iranbotmagic_payloadmalicious scriptphpmyadminportscanproxy scansreconnaissancetelnet

What happened

SANS ISC diary notes several active threats and reconnaissance observed in mid-March 2026: a malicious Bash installer that deploys a GSocket backdoor (delivery vector unknown); honeypot/cowrie logs showing targeted activity from IP 64.89.161.198 (portscans, successful Telnet login, web access) and an unusual payload string containing "MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here"; widespread scans targeting database management UIs (phpMyAdmin and Adminer); and scans attempting to abuse "/proxy/" endpoints, including use of IPv4-mapped IPv6 addresses likely for obfuscation. No CVEs

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
72efc08a274f8ba86436dcf7696fefc0d3b861802a17f168113689f67bd95ca1
Enrichment time
2026-03-23T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd) · Baitaphish