ISC StormCast for Monday, May 13th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 May 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, May 13, 2024 edition of the Santernat Storm Center's Stormcast. |
| 0:08.6 | My name is Johannes Ulrich and today I'm recording from San Diego, California. |
| 0:14.0 | The DEA today had a diary with a follow-up to his diary from last week about using NSLuckup in Windows to debug DNS. |
| 0:24.6 | And so a little detail that's often overlooked in DNS and that trailing dot at the end of a host name. |
| 0:31.6 | A host name contains multiple labels and they're separated by a dot and that trailing dot is actually the root zone. |
| 0:42.2 | If you omitted, then it's not necessarily a complete host theme and a DNS suffix may be added in Windows. |
| 0:51.6 | You can configure what suffixes may be added. That's typically your |
| 0:58.0 | default domain name, the domain name of the network that you are connected to. So a little important |
| 1:04.7 | detail, you better don't forget. This is also important if you, for example, ever ended up editing a bind zone file or something |
| 1:13.2 | like this and you forgot that training dot then the domain name will be added at the end which |
| 1:19.2 | sometimes is what you want but often it then sort of leads to these double domains at the end of |
| 1:27.3 | the host name. |
| 1:29.4 | And the Cybersecurity Infrastructure Security Agency CISA published Joint Advisor is part of the Stop Ransaver effort regarding BlackBasta. |
| 1:42.0 | BlackBasta has recently been seen attacking health care providers in particular. |
| 1:48.4 | What's to me always the most interesting here is the initial access vector. |
| 1:52.7 | In this case, spare fishing quagbot often delivered via spare fishing. |
| 1:58.7 | Quackbott, of course, being far from a new Malware family, |
| 2:03.6 | and then also as of February, this group is exploiting the connectwise vulnerability. |
| 2:11.6 | In some cases, they're also exploiting valid credentials, meaning essentially credential stuffing, so credentials they found |
| 2:19.7 | somewhere else, and of course, multi-factor authentication would be a good way to prevent some of |
| 2:26.7 | these attacks. |
| 2:28.3 | The advisory certainly makes a worthwhile read and should give you some ideas as to how to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

