4.9 • 696 Ratings
🗓️ 18 August 2016
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, August 19th, 2016 edition, the Sands and its Storms Center's |
0:06.5 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Stockholm, Germany. |
0:11.4 | Brad came across an interesting case that he documented in a diary in which one compromised website |
0:18.1 | was used to spread two different exploit kits, one via the pseudo |
0:24.4 | darkleash script and a second one via an injected EITES script. |
0:30.2 | Now it's not uncommon to find that vulnerable websites are compromised multiple times, but in |
0:37.4 | this case literally the |
0:39.3 | exploit JavaScript was right after each other for these typically competing |
0:45.7 | with each other malware campaigns not really clear whether this was the same |
0:51.3 | individual that set up these two links but that's probably the most likely |
0:56.1 | explanation in this case because what we have typically seen in other cases is that particular |
1:02.4 | pseudo dark leach will prevent any other exploit kit from running on the same page either way |
1:09.6 | you'll either end up with the Cripmic Ransomere |
1:13.6 | or with something that Pratt believes was Wattrack variant. |
1:18.6 | That's essentially just a troach that will wait for further instructions down the road. |
1:24.6 | So really just more persistence mechanism. |
1:28.3 | The possible advantage for the attacker is that they will of course get users that are |
1:34.4 | vulnerable to either of the exploits being used here but that comes at a cost in |
1:41.0 | that it's more likely for the exploits to get detected and the user |
1:45.9 | will not even load the page and Brad actually shows how his snort install did |
1:52.6 | trigger on these particular exploit kits and then we have first winter |
1:58.2 | bulletins trickling in regarding the release of the equation crew |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.