meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 5th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 March 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VBS to RAT; Cisco Snort DoS Patch; VMWare View Planer Update; Google FLoC; Supermicro Trickbot Patch

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 5th, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich.

0:09.9

And the time recording from Jacksonville, Florida.

0:14.2

In Diaries today, we have Xavier showing the reverse analysis of a visual basic script that then loads PowerShell, uses

0:23.9

some C-sharp, and in the end, process hollowing in order to end up with complete remote

0:31.2

access.

0:32.3

The initial script is really just a downloader that then downloads the PowerShell script and this PowerShell script, then

0:40.9

downloads a DLL, which in the end will use a C-sharp compiler on the victim's systems

0:48.7

in order to create additional components of the payload.

1:00.4

And the intent of all of these steps is likely to evade detection, of course.

1:06.0

And this script will also specifically detect if it's running in sandbox, i.e., by checking if a particular DLL is present.

1:11.1

And Cisco released a number of updates again to a day.

1:15.1

The one update that's labeled as high is based on a war on a billy that was fixed in

1:23.2

Snort back late last year.

1:26.2

I think September or so, Snort 2-917 had a denial of service

1:32.1

issue with its Ethernet frame decoder. Now, of course, Snort is now owned by Cisco

1:38.5

and integrated in a number of different Cisco products. So these products are the ones that need to be fixed now. And this

1:46.8

includes the 1000 and 4,000 series integrated service routers, Catalyst 8,000 V, 8,200 and 8,300, as well as

1:56.5

cloud services router 1000V and the Integrated Services Virtual Router.

2:03.1

And if attack using this vulnerability and attacker would be able to exhaust disk space

2:09.0

on affected devices.

2:12.6

And VMware patch what it's calling an important vulnerability in VMware View Planner. If exploited, this

2:20.3

vulnerability could lead to code execution. As it says in the advisory, an unauthorized attacker

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.