ISC StormCast for Friday, January 26th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 January 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, January 26, 2024 edition of the Sansonet Storm Center's Stormcast. |
| 0:09.1 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.7 | So we got an interesting info stealer today that Xavier came across and that he wrote up. |
| 0:22.9 | First of all, it does some a little bit unusual geotargeting in that it apparently attempts to avoid Vietnamese users. |
| 0:30.9 | This check is just done by IP address. On the other hand, it also includes a code to look for cookies that are used by a browser popular in Vietnam called Cockcoccus, the name of the particular browser. |
| 0:47.2 | I suspect that this particular malware was written by someone in Vietnam, maybe trying to not get the crosshairs of local law |
| 0:56.5 | enforcement. That's why you often sort of see these specific exceptions. And since this |
| 1:02.5 | browser is popular in Vietnam, the author may have included it because that's a browser |
| 1:09.6 | that the author may use. |
| 1:11.9 | Of course, that's someone speculative. |
| 1:14.7 | But the other interesting part is that one particular type of cookie that it's looking for |
| 1:21.3 | is Facebook cookies, in particular for the ads manager. |
| 1:26.4 | Ads manager.com, that's being used by businesses who advertise on Facebook. |
| 1:33.2 | And I've mentioned this a couple times before that this sort of has become a pretty hot commodity |
| 1:38.6 | credentials for these advertisers because once you own an account that's able to place ads in Facebook, |
| 1:48.1 | you can use this account not just to get free ads, that's of course nice to have, |
| 1:52.3 | but also to then post malicious ads on Facebook. |
| 1:57.5 | And these accounts would then, of course, be disabled after some time. And having |
| 2:03.6 | throwaway accounts that were stolen from legitimate users, of course, makes them quite interesting |
| 2:10.2 | to post ads for malicious tools. This bot does heavily use Telegram's API for command control, which again is nothing really that terribly unusual. |
| 2:22.3 | Telegram has a pretty simple and straightforward API. |
| 2:27.3 | Virus total score for this Malaver is 6 out of 60. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

