meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 29th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 January 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cryptojacking Worm; Slip Streaming 2.0; Shadowsocks Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, January 29th, 2021 edition of the Sansanet Storm Center's Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:14.1

Palo Alto is alerting off a new cryptojacking script that they're calling ProOcean and tribute to the Rock Crew, because

0:25.1

it is very similar to an earlier tool that was released by this crew.

0:31.1

Now, crypto jacking, crypto mining, Malware is of course not really all that new.

0:37.0

This one is a little bit more sophisticated than some of the others that I've seen.

0:41.8

It's going after relatively straightforward vulnerability, like the Apache Active MQ1,

0:49.1

the Oracle WebLogic vulnerability, and then just unsecured Redis instances, but none of these

0:55.6

vulnerabilities is terribly new there from 2016 and 2017. They do target specifically

1:05.5

servers hosted within cloud providers, and they're in particular Chinese cloud providers like

1:13.8

Tencent and Alibaba.

1:16.3

To me it looks like they're pretty much mostly going after systems that are no longer maintained.

1:21.5

Maybe there is a little bit of pattern by trying old vulnerabilities to hit unmaintained machines, because

1:30.7

this particular malware will not just kill competing malware, which is quite common, but it

1:38.1

will also kill other software that uses a lot of CPU.

1:43.2

So if you have some legitimate software running on the host,

1:46.9

you should probably notice that it's all for a sudden stopped running. It uses the standard

1:52.7

XM Rick package in order to mine Monero and another little twist. It then also goes out and tries to infect other systems within the same slash 16 network.

2:07.0

And again, given that, they appear to be targeting systems within specific cloud providers.

2:12.8

This makes a lot of sense.

2:13.8

They probably try to stay within the IP address space that this cloud provider uses.

2:22.3

Palo Alto did publish respective indicators of compromise, but really just watching CPU load and such

2:31.3

probably should do a good job to detect this particular malware.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.