ISC StormCast for Monday, June 12th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 June 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, June 12, 2020, |
| 0:04.0 | edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.8 | For all the reverse engineers among you, we do have a write-up by Xavier about a PowerShell Backdoor. |
| 0:22.4 | This one was not detected by antivirus, and one of the things that made a little bit more clandestine was the fact that it was using the file name that's commonly used for PowerShell profile files. |
| 0:38.2 | PowerShell profiles are being executed whenever you start PowerShell, so it's kind of an |
| 0:43.0 | auto-run-like thing that you run to set up your environment, for example, correctly, and |
| 0:51.0 | it uses a set of reserved file names like in this case Microsoft. |
| 0:56.1 | PowerShell underscore profile. |
| 0:59.2 | .p.s. |
| 1:01.1 | The script itself connects to a command control server. |
| 1:04.9 | It does retrieve cryptographic material then from the command control server and lately connects to receive additional commands. |
| 1:15.9 | And of course, as usual, Xavier has additional details about how to deal with this type of PowerShell script and what it exactly did. |
| 1:25.3 | One item to note, as Xavier wrote up, |
| 1:28.5 | the diary, the particular command control server, |
| 1:31.6 | was actually still active. |
| 1:35.3 | And if you're interested in seeing what to expect, |
| 1:38.6 | if you are running one of our honeypots, |
| 1:41.4 | Guy has a summary of what his honeypot detected last month. So a quick review |
| 1:49.2 | of all the different logs, some of the top tens that he saw and log volume, just to give you |
| 1:54.8 | an idea, kind of all of the attacks that an average IP address tends to be exposed to. |
| 2:03.2 | And then we do have a second vulnerability in Moved. Remember, Movedit, the company behind it, |
| 2:10.6 | Progress released a patch for Moved end of May. It was immediately wildly being exploited in particular by the Klopp |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

