meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, August 26th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 26 August 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Mimikatz/RDPWrapper Dropper; IRS Impersonation; Instagraph Phish; GitHub WebAuthn

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, August 26, 2019 edition of the Sands and Stormzones, Stormcast.

0:07.7

My name is Johannes Ulrich.

0:09.4

And then I'm recording from Jacksonville, Florida.

0:14.4

Xavier came across an interesting smaller attack last week, and in this attack, the using Mimicats for a change in order

0:25.5

to extract users passwords. One credentials were extracted using Mimicats. They were then

0:33.2

infiltrated to an FTP server which was exposed after Xavier was able to retrieve the

0:42.2

credentials from the actual exploit script. Turns out the attack wasn't really all that widespread,

0:49.8

only 53 different infected hosts at this point, but after all, 188 credentials were found in files on the FTP server.

1:00.0

The initial sample that Xavier found was Visual Basic Script, and now how this then ended up on users' systems I think isn't quite clear yet, but of course

1:13.3

there's a number of ways how you could deliver malicious script to a victim.

1:21.5

And the US Internal Revenue Service or IRS is warning taxpayers that they have seen a sort of more interesting malware campaign

1:30.4

that pretends to come from the IRS.

1:34.4

Now usually we see sort of an uptick in these IRS impersonation attacks during tax filing

1:40.2

season.

1:41.0

It's of course kind of late for that, but still a lot of people that still have

1:46.3

to finish up their taxes. In this particular case, the email claims to be an automatic income

1:53.1

tax reminder or an electronic tax return reminder. The email leads the user to an IRS look-alike site. And what probably makes

2:04.2

the entire scheme a little bit more plausible is that the email actually does include a one-time

2:12.0

password that the user is supposed to use to retrieve that document from this fake IRS website.

2:20.4

When the user enters the password, well, the malicious document is delivered and then used

2:25.8

to compromise the victim.

2:28.2

So while it originally kind of looks a little bit like a fishing attack, they're not really

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.