GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
2026-03-22T19:23:47Z•e7b96b4f89488f491809800c5318e8e93856496d8c64aceb21d21f16c3c38be7
64.89.161.198adminerbackdoorbash-scriptcowriegsockethoneypotiocipv4-mapped-ipv6malwarephpmyadminportscanproxy-scanreconnaissancescanningtelnet
What happened
SANS ISC diary items describe multiple reconnaissance and compromise-related observations. Most notably, a malicious Bash installer was found that installs a GSocket backdoor on victims (delivery vector unknown). Honeypot/cowrie logs show scanning, a successful Telnet login, and a distinct marker string ("MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here") tied to activity from IP 64.89.161.198. Additional entries document widespread web scanning for administration panels (phpMyAdmin/adminer), /proxy/ URL abuse, and use of IPv4-mapped IPv6 addresses to obfuscate scans. Overall activity
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- e7b96b4f89488f491809800c5318e8e93856496d8c64aceb21d21f16c3c38be7
- Enrichment time
- 2026-03-22T19:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.