meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 27th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 27 February 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. WebDav Leads to IcedID; oledump msi plugin; Automatic BEC/Ransomware Discrution; Cisco Vulns;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, February 27, 2023 edition of the Sansonet Stormer's Stormcast.

0:10.2

My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida.

0:16.4

On Friday, Brad wrote about iced ID or bogbot and they gave us an update on some of the

0:24.2

latest tricks that this Malbert family is up to.

0:29.4

Aside of using Google Ads, which is sort of one of the infection vectors that has become

0:35.1

already popular, the last few months as the bad guys figured out that's

0:39.3

pretty easy and cheap. Another trick that it's playing with malicious emails is, first of all,

0:46.5

one-note files, another sort of current infection vectors, really popular. And secondly, it's also

0:54.1

using dot- dot URL files.

0:56.9

Another new trick here is that it's using HTTP methods associated with WebDAF.

1:03.1

WebDaf, I believe SharePoint uses it.

1:06.2

I've seen it sort of more in the earlier days of the web to essentially sort of update websites

1:12.2

and the like but the prop find is the htp method that's associated with webdaf that's being

1:21.2

used in these latest attacks and if you are looking at ht traffic, this should really stick out and be something

1:30.1

that shouldn't be too hard to identify as abnormal. More indicators of compromise and other details

1:37.9

you can find in Brad's diary, which of course is linked to in the show notes. And DDA is just not running out of ideas on how to make his famous Oli Dump tool more

1:50.8

useful, not that it's not useful already.

1:55.4

MSI files is the latest file type that DDA added to OLLI Dump via a specific OLLIDump plugin, plugin MSI.Py.

2:07.6

MSI files are essentially Windows installer files, so often used to install malicious software,

2:13.7

and this plugin gives you sort of some basic information,

2:18.1

meta-dida style information from the MSI file to hopefully figure out whether or not a particular

2:23.5

file is malicious or not.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.