GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
ID: 0592b21e-b3a3-5a98-8e1b-42cecf2ee748
STIX ID: report--0592b21e-b3a3-5a98-8e1b-42cecf2ee748
Feed Name: SANS ISC Diary
Threat Score
This report analyzes a malicious Bash script that deploys a GSocket (gs-netcat) backdoor, establishing outbound relay-based C2 communications and implementing cross-Unix persistence and anti-forensic timestamp restoration techniques. The analyst documents the installation paths, cron/profile persistence, embedded helper functions used to track and restore file timestamps, and provides IOCs including file SHA256 hashes and related references.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
