ISC StormCast for Monday, March 5th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 March 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, March 5th, 2018 edition of the Santernet Storm Center's Stormcast. |
| 0:07.3 | My name is Johannes Orich, and I'm recording from Jacksonville, Florida. |
| 0:12.5 | Xagyi came across yet another desktop, a crypto miner that was installed by malware. |
| 0:20.0 | Now what's sort of interesting in this particular case is that |
| 0:24.5 | the malware is fairly protective of the system. Now, this isn't really new where malware is sort of |
| 0:31.7 | deleting, competing malware, but in this case, the malware is trying to get a hold of as much CPU as it can by the leading competing crypto coin miners. |
| 0:43.3 | Now, the way these crypto coin miners are identified is by the process name, so nothing really all too fancy. |
| 0:50.3 | But sort of interesting, it's a pretty good and complete list of these processes. |
| 0:57.1 | So this list actually has a nice defensive use in that you could use this list and then |
| 1:03.8 | look for processes like this on your own system in order to find crypto coin miners. |
| 1:10.6 | And of course, there is almost no online crime these days |
| 1:15.0 | that doesn't touch cryptocurrencies in some way. Also, recent Memcash denial of service attacks |
| 1:22.7 | apparently are asking for ransom to be paid in Monero. So there's only a subset of the hacks that people |
| 1:31.9 | were talking about last week. Not all of the attacks are asking for ransom. Now, how they're |
| 1:37.9 | asking for ransom? Well, the payload of the packets they're flooding you with actually will |
| 1:43.0 | include instructions. |
| 1:45.0 | Now, Akamai who is reporting about this, did say that you probably are better off not paying. |
| 1:52.0 | And the simple reason is that apparently all victims are receiving the same address to send the money to. |
| 1:59.0 | Also, this address has been used in the past, indicating that |
| 2:02.9 | this is an older group that is still sort of riding that wave of asking for ransom in response |
| 2:09.4 | to the Nile of Service at Axe. The problem is because, well, it's just one address. They |
| 2:14.9 | don't really know where the money is coming from. So really not |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

