ISC StormCast for Friday, October 4th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 October 2019
⏱️ 15 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, October 4th, 2019 edition of the Sansonet Storms and StormCast. |
| 0:07.1 | My name is Johannes Ulrich. |
| 0:08.6 | And I'm recording from Jacksonville, Florida. |
| 0:12.9 | Ransomware is the gift that keeps on giving, at least if you are a security analyst. |
| 0:19.8 | But attackers don't always use a new ransomware. |
| 0:23.9 | They sometimes sort of keep reusing older versions and just come up with a new route to get |
| 0:30.6 | people to infect themselves. |
| 0:32.9 | Xavier came across such an example. |
| 0:36.5 | The email advertising the ransomware does follow some of the |
| 0:40.6 | playbook of fake antivirus. It does claim that the user's system is infected and suggests |
| 0:47.1 | that they are downloading a repair tool from Microsoft. The email itself follows standard Microsoft branding. When the user downloads |
| 0:58.4 | this repair tool, they of course download the ransomware and execute it willingly. So no real exploit |
| 1:07.2 | involved here. Now the ransomware being installed here is quite old, |
| 1:11.8 | except he was able to actually find the source code for this particular ransomware on GitHub, |
| 1:18.3 | and it appears to be about two years old. Accordingly, also, Virus Total has pretty good detection |
| 1:25.2 | for this particular variant. |
| 1:29.8 | And last week we got a new version of TCP Dump and it turns out that it fixes a large |
| 1:36.6 | number about 20 different vulnerabilities, some of which are remote code execution |
| 1:42.8 | vulnerabilities. |
| 1:50.9 | Of course, TCPDump is sort of one of those tools we always consider old and stable and, well, secure. Well, they actually have added a lot more application layer protocol intelligence to TCPDump, |
| 1:58.7 | and some of these vulnerabilities at least appear to be related to these new features. |
| 2:05.5 | So definitely if you are using TCPDump, make sure you are using the latest version, 493. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

