ISC StormCast for Monday, March 12th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 March 2018
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, March 12th, 2018 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich and the time recording from San Francisco, California. |
| 0:12.7 | Paying to get your files back after you have been infected by ransomware has always been a dubious |
| 0:19.8 | solution. But if you ever wondered what your chances are |
| 0:24.6 | to get your files back after paying as expected they're not really all that great only about |
| 0:31.6 | half the companies surveyed by security company cyberch got their files back after paying. |
| 0:38.3 | I think this ratio is actually better than what I expected. |
| 0:43.3 | The good news, most of the companies got their files back without paying by essentially just restoring from backups. |
| 0:51.3 | Well, I always take surveys like this with a grain of salt and this one particular, |
| 0:58.3 | not really clear whether or not they did anything closely scientific here or just surveyed their |
| 1:04.5 | customers. The lesson here that I think is definitely valid is that good backups give you a better chance of recovering your files |
| 1:14.4 | than paying the ransom. And actually, one thing that I've seen a lot with ransomware, |
| 1:20.1 | if you do catch it quickly enough, there is a good chance that many of the files are actually |
| 1:25.6 | not encrypted at all. They just change the file name, so that's another way to get some of your files back |
| 1:32.8 | if the backups don't work out. |
| 1:36.1 | Now, we have seen somewhat regularly vulnerable routers used to further compromise networks. |
| 1:42.6 | One of the most common and simplest methods this is usually done is by DNS changers |
| 1:49.7 | that change the DNS setting off the router, and then of course those settings may |
| 1:54.4 | propagate into the network via DHCP. |
| 1:58.4 | But Kerski came across a new piece of router malware that appears to be more |
| 2:03.7 | targeted in particular aimed at SIS admins. The malware affects routers made by Microdic and spreads |
| 2:12.6 | to the Sysadmin via the admin utility used to manage the router. So not via DNS settings, the administrator has to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

