meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, September 16th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 16 September 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. #RigEK -> VBScript; Pentesters Arrested; iOS 13 Unlock Trick

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, September 16th, 2019 edition of the Sansanet Stormeners Stormcast.

0:08.5

My name is Johannes Ulrich.

0:10.1

I'm recording from Stockholm, Germany.

0:13.9

This weekend, Xavi took a look at a Rick Exploid kit that delivered a malicious visual basic script to one of his users.

0:24.9

Couple things that sort of tipped him off here that this was probably malicious.

0:30.3

The entire infection started out with a set of redirects to various .xyc domains. Dot XYC domains are quite popular among malicious websites,

0:43.9

just because they're cheap to use. But on the other hand, I haven't really seen a lot of good

0:49.6

stuff with dot XYC as top level domain, so that may be something that you want to take a look at.

0:58.0

It also appears to use a number of little tricks to make analysis a little bit more difficult,

1:03.5

short of actually visiting the malicious site, like for example, checking whether or not you're

1:10.0

using the correct browser that you're claiming to use.

1:14.4

And then as typical for exploit kits, it uses a number of different vulnerabilities to try to infect the system.

1:23.3

Like, for example, a flash file, also a PowerShell script is being used.

1:28.5

And it also tries to take advantage of the CSE.E.exe compiler that's part of the dotnet framework

1:37.6

that's often installed on systems. And actually just happened that Xavier has written about this particular technique. I believe it was

1:47.4

as recently as last week. So probably the easiest way to detect this particular type of attack

1:54.9

is looking for these dot XYC domains a little bit more closely. IP address not all that useful here because the malicious sites, at least part of them,

2:06.0

were hosted behind Cloudflare.

2:09.6

And whenever I am talking about penetration testing in class,

2:14.2

I usually mention the importance of permission and actually having permission

2:19.9

that covers the entire scope of the engagement.

2:24.2

Now, yes, people talk a lot about possible criminal charges, but often the more common

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.