ISC StormCast for Monday, August 16th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 16 August 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, August 16, 2021 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.2 | My name is Johannes Ulrich and I'm recording from Sevalde, Germany. |
| 0:13.9 | Guy this weekend took a look at some attacks that he observed against his honeypot, |
| 0:20.3 | hitting an e-discovery endpoint for exchange. |
| 0:25.2 | Now, this particular endpoint can sometimes be used to retrieve messages if this feature is |
| 0:31.5 | enabled and not properly secured. So no authentication may be required in this case. It's, I actually don't think |
| 0:41.3 | the particular CVE that Ghee suggests here that they are after, but that particular vulnerability |
| 0:49.2 | was patched just around the time when Gie first saw these scans starting. So there may be some |
| 0:56.4 | relationship here between that particular patch Tuesdays, patches and these scans. The scans are |
| 1:04.6 | originating from one particular network at Digital Ocean and that network is actually used by a group that identifies itself |
| 1:13.0 | as trying to identify organizations exposed services. |
| 1:18.1 | They're going by the name of stratoid.com, but don't really know much about that particular |
| 1:25.1 | company or organization. |
| 1:28.3 | And on Friday, we got yet another great walkthrough by Pratt through the latest version of Danabot. |
| 1:35.4 | Danabot is an infest dealer. |
| 1:37.5 | It's going after banking information typically. |
| 1:41.5 | And in this particular case, Pratt is walking you through how to analyze a Danabot infection that was triggered |
| 1:50.0 | originally by a malicious email. And we got a really interesting paper by several researchers |
| 1:58.0 | from the University of Maryland and the University of Colorado Boulder, |
| 2:02.6 | they looked at amplification attacks that could be caused by middle boxes. |
| 2:08.8 | Middle boxes are often thought of as proxies, but often they are actually not proxies in the |
| 2:15.5 | original sense, but really sort of more deep inspection firewalls, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

