ISC StormCast for Friday, December 30th 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 December 2016
⏱️ 4 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, December 30th, 2016 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.3 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:11.8 | We've got some reports today from readers and also confirmed that with our own data that there appears to be quite a bit of increase in GRE traffic or generic route encapsulation. |
| 0:23.0 | That's a protocol 47 over IPV4. Now typically this protocol can be used to encapsulate anything |
| 0:31.1 | within IPV4 after this IP header. You then have sort of a short header with essentially just the |
| 0:38.0 | ether type of whatever comes next. |
| 0:40.6 | In this case, the embedded payload is again another IPV4 packet that then carries a random |
| 0:47.8 | UDP payload. |
| 0:49.4 | Don't really see any pattern in this yet. |
| 0:51.8 | It's not at the level where I would call it a denial of service. Not |
| 0:55.9 | really sure what this is about, really just looks like random traffic. Now, Mirai has sent |
| 1:02.1 | some traffic like this in the past and also other denial of service tools have used GRE, |
| 1:08.7 | but not really clear if this is related at all at this point. |
| 1:13.1 | If you do have any packets, or in particular, if you see any outbound traffic from your |
| 1:17.6 | network matching that description, we would be really interested to hear from you to see |
| 1:22.2 | where this all originates. |
| 1:24.7 | And the USR today released a fairly detailed report about some of the hacking activity |
| 1:31.0 | against US political parties last year. They attributed to what they call Chris Le Steppe, which is two |
| 1:38.4 | different actually Russian hacking groups. The report is very detailed and nicely outlines many of the attack techniques |
| 1:46.3 | that were used in this particular attack. So I do recommend that you read it. Don't get distracted |
| 1:52.8 | by the politics around this. The report really has quite nice details about how these |
| 1:58.9 | more advanced attacks work. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

