GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
2026-03-22T07:23:46Z•91f46bd6bc068140a273cd39096f63bc91fffb920af2e507f09b6abe0aa3b417
DShieldGSocketLinuxadminerbackdoorbash scriptcowriehoneypotindicatorsipv4-mapped-ipv6iranbotmalicious scriptnetwork reconnaissancephpmyadminproxy-scansscanningtelnet
What happened
SANS ISC diary entries (Mar 16–20, 2026) report multiple attacker activities. Key item: discovery of a malicious Bash script that installs a GSocket backdoor on a victim Linux host; the delivery vector and origin are unknown. Other reports from honeypots/cowrie and DShield include a notable message string ("MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here") and activity from IP 64.89.161.198 between 30 Jan–22 Feb 2026 (portscans, successful Telnet login, web access). Additional entries describe widespread scans targeting adminer/phpmyadmin, proxy URL abuse (including use of IPv4-maped
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 91f46bd6bc068140a273cd39096f63bc91fffb920af2e507f09b6abe0aa3b417
- Enrichment time
- 2026-03-22T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.