meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 2nd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 2 April 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Quakbot; TPOT and DShield; MacOS ssh; Cloudflare DNS; Zoom Leaks NTLM Hashes

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, April 2nd, 2020 edition of the Sansonet Storms on Stormcast.

0:07.1

My name is Johannes Ulrich.

0:08.7

And I'm recording from Jacksonville, Florida.

0:12.9

Let's try today to have a couple stories that are not related to the coronavirus.

0:17.7

And the first thing we have is a good old quackbot, mal-spam that Pratt analyzed.

0:24.9

Now, this is typically sent from infected Windows hosts.

0:29.3

So one of the things that Malware, of course, does if it infects a host, is to use these hosts to send spam itself.

0:41.3

So Pratt goes as usual in quite a bit of detail as he walks through the different aspects of disinfection. This particular mal-spam is sending fake

0:49.2

water phone emails and also some of these DHL shipping notifications.

0:55.9

So he's explaining how to analyze this using virus or extracting the email messages and

1:02.7

figuring out what additional payloads are being downloaded.

1:10.0

And Tom is telling you how how to enable submitting the shield logs from teapot.

1:16.4

Teapot is a honeypot that incorporates a number of different sort of pieces of honeypot software

1:23.4

and a pretty neat elastic stack to analyze it all.

1:28.3

So a little bit more heavy weight there, but pretty neat,

1:32.3

and really not that difficult to enable submitting the shield logs using this honeypot

1:39.1

just by enabling it in Cowry, which is, of course, one of the components that teapot uses just like our own Honeypot to emulate S.H and Telnet.

1:51.0

And talking about S.S.H since S.H is so often scanned, one of the tricks of course that many users are using is to run the SSH server on some random

2:03.6

high port. This may cause some issues with the latest update of macOS, 10154, according to a blog

2:12.9

post published by Tyler Hall. Now, I wasn't able to reproduce the exact behavior that he described, but there are a couple

2:21.2

other similar posts, so hope it wasn't just a bad April Fool's joke.

2:26.9

What he observed was that if SSH is listening on a port that's greater than 8,1001.92. And if you are connecting to the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.