meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 21st, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 21 April 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Quakbot and DarkVNC; Java Psychic Signatures; Snort Modbus DoS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, April 21st, 2022 edition of the Sansonet Storm Center's Stormcast.

0:08.3

My name is Johannes Ulrich, and I'm recording from Marriester, Florida.

0:14.1

Prior today, published a diary with a recent version of Quagbot or QBot.

0:20.3

Now, at this time, Quagbot was used to install DarkVNC.

0:26.4

As so often it started with an email and a link, the victim then download a SIP archive

0:32.2

that contained an Excel file, and then of course macros were used to download the Quagbot DLL files.

0:41.0

After checking connectivity, which interestingly used the openssel.org website, it then

0:47.9

established command control traffic and installed DarkVNC.

0:54.1

Dark VNC as the name implies, well, it is VNC.

0:57.5

It allows a full desktop remote access, but with traditional VNC, the regular user of

1:05.5

the workstation may notice the activity.

1:08.9

With dark VNC.

1:17.0

You typically have a second desktop that's of a hidden desktop that's being set up that the attacker controls and the victim does not notice that there is a second user connected

1:24.2

to their system.

1:26.5

Typically that's then being used for banking malware and the like.

1:30.3

By using the victim's desktop, you're actually able to bypass some of the checks

1:36.3

because you already are using the correct IP address.

1:39.3

You're using some of the cookies that the website may leave behind, making credential theft so much

1:47.1

easier.

1:48.2

In the case of compromise, as well as samples, and of course anonymized P-CAPs are available

1:54.8

for download.

1:57.8

Yesterday, I talked about the Oracle quarterly Critical Patch update and how it included some updates for Java as well.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.