4.9 • 696 Ratings
🗓️ 10 December 2021
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, December 10th, 2021 edition of the Sandstone Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:14.8 | Henry Jing today did publish an interesting blog post regarding some fishing messages on Discord. Of course, |
0:23.6 | fishing tends to follow users to whatever messaging platform they're using, so no real surprise |
0:30.3 | that they have now weaponized Discord as well. And this particular fishing attempt was a bit more on the sophisticated side. |
0:40.9 | First of all, the username used within Discord was security with a couple sort of sparkles |
0:48.3 | at the end. |
0:49.0 | But then they advertised free Nitro and offered a link that actually used the domain name |
0:57.4 | Discordgifts.1. |
1:00.8 | So something looking a little bit plausible. |
1:04.0 | If the user did reach the website that they advertised, they were then asked for billing information, credit card data, |
1:13.9 | which appear to be sort of real, the goal here to steal credit card information. And then in the |
1:19.9 | end, the user was sort of left hanging with a 500 error. Also kind of interesting if you |
1:26.8 | used the website without sort of the additional parts to the |
1:31.7 | URL that were posted to the channel, you were just directed to the legitimate Discord website, |
1:39.8 | and that of course, again, then makes that entire scam more plausible. |
1:47.1 | They also, in their domain name, sort of swapped the CNS, so DixS instead of Discord, |
1:53.1 | guess they wanted to avoid some of the automated tools that Discord usually uses in order to find these fishing sites |
2:00.1 | by, for example, looking |
2:01.5 | for newly registered domains or certificate transparency logs. |
2:07.4 | And Eclipse, a company that specializes on firmware security, did take a look at why |
2:14.0 | microtick devices are still so commonly being exploited. Well, the summary is, first |
2:20.7 | of all, they're attractive. Microtic, if you're not familiar with it, they're making switches |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.