ISC StormCast for Friday, August 12th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 August 2022
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, August 12, 2022 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.5 | My name is Johannes Ulrich, and today I'm recording from, as usual, Jacksonville, Florida. |
| 0:15.2 | Xavier today wrote up a diary analyzing a recent Info-Steeler he came across. The InfoSteeler took advantage of a couple |
| 0:24.1 | common and not malicious tools to bypass detection. First of all, it used a good old Bits admin |
| 0:33.8 | binary to download a tool called N-sudo. Bits admin, of course, very famous. It's used to download a tool called N-Sudo. |
| 0:38.0 | Bits admin, of course, very famous. |
| 0:40.3 | It's used to download Windows patches, but it can also be used just like Curl or W-Get |
| 0:47.8 | on Unix systems to download arbitrary files via HTTP. |
| 0:53.8 | Now, EnSudo, not so commonly installed on Windows system, |
| 0:57.9 | but as the name implies, it's kind of the Windows version of pseudo. Now, works different. It |
| 1:05.5 | sort of allows it to run commands at different privileges, either from a little GUI tool or on the command line. |
| 1:13.7 | And that's sort of how the tool was used here by the malicious code. |
| 1:17.7 | Now, the script that the user here first initially ran after downloading EnSudo checks |
| 1:25.4 | if it's actually able to run without alerting the user, |
| 1:29.7 | because UAC may otherwise pop up warnings. |
| 1:33.4 | If there is no warning, then the script will be used to adjust various system settings |
| 1:39.7 | before downloading the actual InfoSteeler malware. |
| 1:44.8 | The InfoSteeler will exfiltrate a screenshot of the system, the system's location. |
| 1:49.8 | So of kind of the standard things that InfoSteeler's exfiltrate browser configuration, |
| 1:55.2 | also sort of of an interest may give us a hint as to who did hacker. |
| 2:00.2 | It also appears to be interested in gaming applications like Steam and Minecraft. |
| 2:08.3 | And as I said many times before, I usually do not cover preaches here on this podcast unless we learn something from it. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

