ISC StormCast for Friday, April 26th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 April 2024
⏱️ 20 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, April 26, 2024 edition of the Sansonet Storms |
| 0:07.3 | Sunners Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.2 | Quick a reminder day from Jesse that even on a honeypot, the fireball configuration matters. It's less a matter of blocking or allowing certain ports, |
| 0:24.8 | but redirecting traffic to appropriate listeners. |
| 0:28.8 | The honeypot we are using is taking a page here from Cowry, |
| 0:33.3 | where you are using IP tables in order to redirect traffic to individual ports that we have, |
| 0:39.9 | things like Cowrie and our web honeypot listening on. |
| 0:43.9 | That way, if the firewall rules are not configured correctly, |
| 0:48.2 | you may miss quite a bit of traffic, and that's what Jesse observed in his Asia cloud-based honeypot. |
| 0:58.9 | Black X is a little bit older bot net originally coming out in 2020, in March 2020. |
| 1:07.4 | Sofos wrote about it, and it had a couple interesting properties one was that it's one of |
| 1:12.8 | those bots that actually propagates over USB sticks so if you connect the USB stick to an |
| 1:18.9 | infected system it copies itself and then could potentially be launched on a new system as the USB stick |
| 1:27.4 | is being moved. |
| 1:29.5 | Now, as of late last year, this botnet was really sort of considered somewhat dead |
| 1:34.5 | because it only communicated with one specific IP address as a command control server. |
| 1:40.0 | Well, it turns out that Sequoia has taken over that IP address. |
| 1:46.1 | It was hosted with Green Cloud, so they pretty much just set up an account with them and had |
| 1:51.4 | themselves assign this IP address. |
| 1:54.4 | And since September last year, they're using it as a sinkhole to basically learn more about |
| 1:59.5 | this particular botnet. |
| 2:01.9 | Sadly, it always happens that there are still thousands, if not hundreds of thousands of systems |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

