ISC StormCast for Monday, October 28th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 October 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, October 28, 2019 edition of the San San Antonio Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich. |
| 0:09.7 | And today I'm recording from Santa Monica, California. |
| 0:13.9 | If you got an interesting detect that Guy wrote up this weekend, these are requests to his honeypots that do include a somewhat unusual |
| 0:23.6 | BS underscore real underscore IP header. |
| 0:27.6 | Now first of all, it's somewhat unusual to have headers with underscores instead of dashes |
| 0:33.6 | in them, and then secondly, this particular content was double Bay 64 encoded. |
| 0:43.0 | Now, once they coded, it revealed two IP addresses. One of the IP addresses was the source of |
| 0:50.2 | the traffic. The second one, well, not really clear what it does, but appears to be a scanner |
| 0:56.7 | for web servers. So what's possibly happening here is that this is some kind of proxy chain |
| 1:03.7 | that keeps adding IP addresses and probably each time sort of base 64 encoding this particular |
| 1:10.5 | header. |
| 1:11.7 | Quick Google search showed that this header was seen the first time about a year ago. |
| 1:16.9 | Like last September was of the earliest entry that I found, but couldn't link it to a particular |
| 1:22.9 | tool. |
| 1:23.4 | If anybody knows, please share. |
| 1:26.3 | And Rob wrote a diary talking about how to parse DNS logs in a Windows environment. |
| 1:34.0 | So first of all, how to enable the logging on your Windows DNS server, and then how to use |
| 1:39.4 | PowerShell to parse the logs. |
| 1:42.5 | Interestingly, in the example that he found, he did run into some odd issues, odd DNS requests |
| 1:51.2 | from a switch, and that switch may actually have been infected, but that particular part |
| 1:59.3 | of the investigation is still outstanding. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

