ISC StormCast for Friday, January 26th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 January 2018
⏱️ 18 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 26, 2018 edition of the Sands and its Storm Centers. |
| 0:07.2 | Stormcast, my name is Johannes Ulrich. |
| 0:09.2 | I'm recording from Jacksonville, Florida. |
| 0:12.5 | Xavier today came across an interesting site that offers ransomware as a service. |
| 0:18.0 | All you have to do is provide a Bitcoin address to which the ransom will be paid, |
| 0:22.8 | how much ranch them you're asking for, and then it will create the binary for you. Now, the particular |
| 0:29.5 | site that Xavier found here didn't seem to be quite operational. For example, the support address |
| 0:36.5 | is just example at example.com. |
| 0:39.4 | Now, the guys that run the website will keep 10% of the ransom for themselves, so for that |
| 0:45.0 | you probably should expect better support. |
| 0:48.3 | But Xavier then turned around and looked at if he could find some samples on via Google. |
| 0:55.0 | And sure enough, he got across a couple of examples |
| 0:59.0 | that did match this particular pattern, |
| 1:03.0 | and well, sure enough, it was your standard ransomware. |
| 1:07.0 | Interesting sort of that this particular ransomware is compiled for 64-bit versions of Windows. |
| 1:15.3 | Microsoft's anti-Malver, which Xavier left enabled on his test system, did not actually detect |
| 1:22.5 | this particular malware. If you ever scripted an HTTP request, chances are you used lip curl or variation or wrapper |
| 1:32.3 | around it. |
| 1:33.3 | Well, a lip curl apparently had an interesting security flaw ever since it was first released |
| 1:39.3 | in 1999. |
| 1:42.3 | The problem here is what happens when lip curling counters redirect. What lip curl does if it's |
| 1:48.8 | configured to follow redirects is it sends the same request to this new URL, including all |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

