GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)

2026-03-22T19:23:47Ze7b96b4f89488f491809800c5318e8e93856496d8c64aceb21d21f16c3c38be7
64.89.161.198adminerbackdoorbash-scriptcowriegsockethoneypotiocipv4-mapped-ipv6malwarephpmyadminportscanproxy-scanreconnaissancescanningtelnet

What happened

SANS ISC diary items describe multiple reconnaissance and compromise-related observations. Most notably, a malicious Bash installer was found that installs a GSocket backdoor on victims (delivery vector unknown). Honeypot/cowrie logs show scanning, a successful Telnet login, and a distinct marker string ("MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here") tied to activity from IP 64.89.161.198. Additional entries document widespread web scanning for administration panels (phpMyAdmin/adminer), /proxy/ URL abuse, and use of IPv4-mapped IPv6 addresses to obfuscate scans. Overall activity

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
e7b96b4f89488f491809800c5318e8e93856496d8c64aceb21d21f16c3c38be7
Enrichment time
2026-03-22T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th) · Baitaphish