meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, April 22nd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 22 April 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Crypto Clipboard Swapper; AWS log4j Bug; Psychic Sig PoC; ALAC Audio Decoder Bug

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, April 22nd, 22nd, 22nd, 2022 edition of the Sansonet Stormsendor's

0:08.3

Stormcast. My name is Johannes Ulrich, and today I'm recording from Marietester, Florida.

0:15.6

Xavier today has a post showing how Python may be used maliciously even on Windows. Of course, we have

0:22.4

talked about similar issues before. However, Python, I think we most of the time talk about it

0:29.8

as a defensive tool and scripting language that we are using to find bad things in this case.

0:35.8

Well, the bad guys like it too.

0:38.3

This particular Python script was created for Windows.

0:42.3

It does achieve persistence by scheduling a task, and then it also hides its window,

0:52.3

so a user doesn't notice that the task is running in the background.

0:59.0

And then it's actually a very simple and not very complex script.

1:03.6

All it does is it waits for a cryptocurrency address to show up in the clipboard, and then it replaces that address with one of its own.

1:15.2

It's not just going after the big cryptocurrencies like Bitcoin and the like, but there has about a

1:23.3

dozen different cryptocurrencies that it's looking for. It has patterns in order to recognize

1:30.7

the right addresses and then as soon as it sees it, it will just replace it. Luckily, it doesn't

1:38.2

seem to be working too well. I looked at the Bitcoin addresses and didn't see any deposits for the four Bitcoin addresses

1:47.3

that it's using.

1:49.6

So maybe it was just a test, but certainly appears to be working and has a very low virus

1:57.0

total recognition rate of only three or so of the virus scanners identifying it as malicious.

2:06.8

And back in December when we were all worried about log for J Amazon came up with a hot patch for

2:15.4

AWS and what essentially was supposed to do is it was supposed to disable

2:20.4

JNDI and mitigate the log for J-Warnability for any Java applications that people were running inside

2:30.6

containers. In order to do that, of course, it had to run with elevated privileges.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.