ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd)
2026-03-23T19:23:48Z•e4a6d9f397078cd92b38d4a1b623f48de96783acadf45c00b7f529b323777be4
GSocketadminerbackdoorbash scriptcowriehoneypotioc:64.89.161.198ipv4-mapped-ipv6iranbotphpmyadminportscanproxy scanstelnet
What happened
SANS ISC diaries (Mar 16–23, 2026) report multiple attacker activities: a malicious Bash script was found that installs a GSocket backdoor (delivery vector unknown); Cowrie/honeypot logs recorded an unusual payload string ("MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here") and activity from IP 64.89.161.198 including portscans, a successful Telnet login, and web access; widespread scans for adminer/phpmyadmin and /proxy/ URL probing were observed; attackers are also using IPv4-mapped IPv6 addresses likely to obfuscate origin. Several ISC Stormcast podcast entries were also published.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- e4a6d9f397078cd92b38d4a1b623f48de96783acadf45c00b7f529b323777be4
- Enrichment time
- 2026-03-23T19:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.