meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, June 10th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 June 2019

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. WMI Logs; DNS Logs and Sysmon; Komodo Wallet Highjack; MSFT SOC Lessons #MSFT #DNS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, June 10th, 2019 edition of the Sansonet Stormsendos Stormcast.

0:06.8

My name is Johannes Ulrich, and I'm recording from Neptune, New Jersey.

0:12.7

We've got some feedback regarding the Goldbrood bot scanning for open RPP servers that we wrote about last week.

0:20.9

One user via Twitter reported what looks like a slightly modified payload that included

0:27.8

sort of jihadist spam, also a lot of other random text.

0:33.6

We downloaded payload that our variant offered actually several times from different systems,

0:40.5

different IP addresses, and never really got anything different.

0:44.4

So never really saw any purpose in this bot beyond just scanning and enumerating, essentially,

0:54.0

vulnerable RDP servers.

0:56.8

So for everybody who reported this other variant seems to refer to the same GitHub repository.

1:02.8

So it seems to be a single source at this point that offers this variant with more of a payload.

1:10.6

In weekend diaries, we got two logging-related data. this variant with more of a payload.

1:15.3

In weekend diaries, we got two logging-related diaries. First one by Xavier about WMI logs.

1:19.5

WMI, short for Windows management instrumentation, is remote management technology built

1:25.7

into Windows, and well, of course, Malver likes that

1:29.5

as well. So logging WMI activity is certainly important. Now, Xavier shows how to enable event

1:38.1

tracing for WMI to get more meaningful logs. Otherwise, you really only get sort of failed access to WMI.

1:47.7

Xavier also points out that if you do actually enable event tracing, since it's a debugging

1:53.9

feature, it's intended to only run for a short time, and Windows will by default only collect 8 kilobytes worth of WMI tracing logs.

2:06.7

The second logging-related diary comes from Dilliers. He points out that Sysmon will add DNS logging

2:15.0

to an upcoming release of SIS internals.

2:20.3

Now, I've mentioned logging DNS traffic multiple times here in the podcast.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.