meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 6th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 6 April 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Attackers Chasing Whitelists; Struts2 Vuln Installing Cerber

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, April 6, 2017 edition of the Santonet Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.6

Xavier has an interesting diary about how attackers are going after sites and indicators that are commonly whitelisted. For example, the top

0:24.3

1,000 most popular sites, these sites are often whitelisted, but you'll find sites like

0:31.8

Twitter and GitHub or such among these sites, which of course can also be used as command and control channels,

0:40.3

which of course makes it more difficult for the analyst to really filter out what's going on.

0:46.2

Same of course for URLs.

0:48.1

A lot of ransomware, for example, uses search.php or URLs like that that are very commonly used in

0:58.4

non-malicious sites. So again, this makes not a great indicator to find malicious or infected hosts.

1:07.3

And earlier today, to get ready for the webcast, we'll have later on Thursday about the struts too vulnerability.

1:15.0

I was looking through my honeypot logs again and I saw that there's quite a bit of activity that's actually targeting Windows servers with ransomware.

1:25.1

In this particular case, they tried to install the Kerber Ransomware on the host

1:32.3

that claimed to be vulnerable for these threats to vulnerability. A Google search will show you

1:39.3

how others have reported this last a few days as well. This morning when I ran this

1:47.6

ransomware first in my little honeypot, Windows system that actually has antivirus installed,

1:54.6

it still slipped past the antivirus. Antivirus coverage wasn't that great. End of the day

2:00.2

to day, that's no longer true.

2:02.3

We do now have pretty good coverage for this variant.

2:07.0

And researchers at Kaspersky are reporting about an interesting compromise of a Brazilian bank.

2:14.4

Apparently, this bank lost control over all 36 domains it uses to do business with.

2:22.7

Once attackers had control of these domains, they were able to redirect traffic to these domains

2:28.6

at will, they were able to intercept email, and most importantly, they were able to intercept HTTP requests to the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.