ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd)

2026-03-23T19:23:48Ze4a6d9f397078cd92b38d4a1b623f48de96783acadf45c00b7f529b323777be4
GSocketadminerbackdoorbash scriptcowriehoneypotioc:64.89.161.198ipv4-mapped-ipv6iranbotphpmyadminportscanproxy scanstelnet

What happened

SANS ISC diaries (Mar 16–23, 2026) report multiple attacker activities: a malicious Bash script was found that installs a GSocket backdoor (delivery vector unknown); Cowrie/honeypot logs recorded an unusual payload string ("MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here") and activity from IP 64.89.161.198 including portscans, a successful Telnet login, and web access; widespread scans for adminer/phpmyadmin and /proxy/ URL probing were observed; attackers are also using IPv4-mapped IPv6 addresses likely to obfuscate origin. Several ISC Stormcast podcast entries were also published.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
e4a6d9f397078cd92b38d4a1b623f48de96783acadf45c00b7f529b323777be4
Enrichment time
2026-03-23T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.