meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 26th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 26 February 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Magellan Scans; Mouse Sandbox Check; Salesforce Apex Vuln; IBM ODM PoC; Linux kTLS Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, February 26, 2024 edition of the Sandsenet Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

Did he finally found a solution for a problem that we have been chasing for almost two years and that's scans that

0:24.1

contained the string MGL and DD. These scans were not obviously malicious. There was no obvious

0:30.8

purpose of this string. It for example showed up as an HTTP, which of course is not defined, typically not causing anything to happen.

0:43.2

Well, thanks to a reader Mikhail Solitzik for reaching out.

0:48.3

Mikal did actually record a video about a tool that is created by Ripe, the European Network Agency.

0:57.4

It's a little bit sort of like R.D. Shield Honeypots, but what they're distributing is

1:03.1

what they're calling Ripe Atlas. It's a little computer sort of Raspberry Pi-like.

1:09.6

It's actually a little bit smaller, that you can connect

1:12.3

to your network, and then they, and researchers are able to use it to basically run various

1:19.5

network tests to check Internet responses, Internet response time, and various other things.

1:26.7

One of the tools installed on Ryeb is Magellan, and Magellan allows you to send

1:33.8

packets with various protocols like DNS, HP and such, with that particular string, MGL and

1:42.1

DD, identifying them as being originating from Magellan.

1:48.0

This is, again, just sort of part of an Internet measurement effort.

1:52.4

It's not malicious.

1:54.4

Also sort of not really used as a port scan or things like, you know, we have on Friday I mentioned

2:00.5

of some of the other researchers,

2:02.4

Chaudan and the like that really are looking for open ports.

2:07.5

And Xavier brings us yet more malware.

2:10.5

We always love malware in particular if it's being analyzed by Xavier.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.