meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, December 2nd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 2 December 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Agent Tesla; SauronEye; Splunk Y2k20 Bug; Google Threat Analysis Group Summary

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, December 2nd, 2019 edition of the Sansonet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and today I'm recording from San Francisco, California.

0:13.2

This weekend, we got two diaries to talk about. First one by Pratt about an ancient Tesla sample that he found. This sample arrives disguised as

0:25.7

an installer for the messaging application Discord. Brad came across the sample via the

0:33.9

Any Run sandbox, so he already had the packet capture file from Eniron and didn't have to create his own.

0:42.5

Agent Tesla is an information stealer.

0:45.6

And it typically exfiltrates information as an email.

0:50.5

Now, to avoid networks that block port 25, Agent Tesla uses the submit port on 587, which is usually allowed outbound, unlike Port 25.

1:04.9

And, well, lucky for Pratt, the SMTP traffic for Agent Tesla was not encrypted, at least not for this variant.

1:15.6

Looks like this makes a nice quick sample to test basic packet analysis skills in Vyershark.

1:21.9

So if you are interested in that, feel free to follow the link to the PC-CAP that Brad lists in his diary. Like most

1:31.3

malware, I come across these days. Again, this malware does not actually exploit any vulnerabilities

1:38.3

per se, but just requires that the user cooperates and installs it.

1:51.0

Now, the second diary from this weekend comes from Russ's tool reviews.

1:54.4

This time, he is looking at Soren. I also have this tool called the Eye of Soren based on where the name already comes from,

2:00.6

a tool that searches files

2:02.5

on a system for sensitive information.

2:06.3

Ancient Tesla, for example, limits itself to exfiltrating information from a few very specific

2:14.0

well-known locations.

2:16.1

But all too often, users keep Word or Excel documents on their systems or on file shares with sensitive data like passwords.

2:25.3

Sor and I will find these documents and assist in exfiltrating the data.

2:31.3

The exfiltrated data volume is quite small as a result because it just picks those

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.