meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 20th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 20 May 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Bumblebee via TransferXL; MSFT OOB Update; SonicWall SMA1000; QNAP Deadbolt; DOJ Policy Update; Exposed Kubernetes

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, May 20th, 2020 edition of the Sandsenert Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

Got yet another great diary from Pratt today, and Pratt took a look at the Mal malware that is using the transfer XL service.

0:24.6

Transfer Excel is a legitimate file transfer service, but like so many similar services, it is often

0:31.6

also being abused to transfer malware. And that's particular what of course Brad was looking into here, and he zoomed in on the

0:43.3

bumblebee malware that he looked at before.

0:46.3

And a particular sample that Brad ran into here is related to a threat group that Google

0:53.3

calls Exotic Lillian

0:55.5

has recently written up as in particular taking advantage

0:59.3

services like Transfer Now, Transfer Excel, We Transfer OneDrive, and of course other similar services.

1:08.0

In the sample that Pratt looked at the malware that's being downloaded from Transfer

1:14.2

Excel is arriving as a SIP file. Once you extract it, we have yet another ISO file, which then

1:22.5

when you double-click it, actually does the good old shortcut trick to then run a hidden DLL and that's when Brad first

1:32.2

saw the bumblebee command control traffic and then later Cobalt strike. As usual, Brad gives

1:39.5

you access to packet captures, indicators of compromise and lots of other details related to this particular

1:48.5

infection. And Microsoft today released an out-of-band update not to fix a new security vulnerability,

1:55.7

but to address an issue that cropped up with the May Patch Tuesday update.

2:03.6

One particular problem here was that people experienced authentication issues with active directory,

2:11.6

and this new patch now fixes these problems.

2:16.6

This is important because organizations have delayed rolling out the

2:20.6

update and this problem affected in particular the fix for CVE 2022, 26923, which was the

2:31.1

surrey fright issue that we have an active exploit available for.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.