ISC StormCast for Thursday, August 15th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 August 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, August 15th, 2019 edition of the Sansonet Storm Center's |
| 0:07.0 | Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. |
| 0:13.0 | Brad today looked at the latest payload being distributed by the Rick Exploid kit and turned out to be Medusa HTTP. |
| 0:23.6 | Now, this malware itself has been around a couple years but hasn't really shown up much |
| 0:30.6 | and it has a somewhat unique command and control channel which sort of is responsible for the |
| 0:36.6 | HTTP part. Or all, it is responsible for the HTTP part. |
| 0:38.1 | Overall, it's used for denial of service, but what's particular unique about this particular |
| 0:45.6 | payload is that it uses the HTTP 100 continue response code, which you typically don't see in normal web traffic. |
| 0:57.0 | So this would make a pretty good indicator of compromise likely. |
| 1:01.0 | In general, the protocol looks very much like HTTP. |
| 1:05.0 | I would call it an HTTP-like protocol. |
| 1:08.0 | It uses posts, it uses HTTP headers and the like. |
| 1:11.6 | Like I said, that 100 continue is a little bit odd and then it also breaks up the request |
| 1:18.6 | into two parts, one up to the expect 100 continue line and then it continues with the request |
| 1:26.6 | well as the spec actually suggests after |
| 1:30.3 | the 100 Continual Response Code is received. |
| 1:35.3 | Then returns a cookie which actually does include the host's public IP address. |
| 1:42.3 | So kind of interesting signaling going forth and back shouldn't be too |
| 1:45.8 | hard to spot and then of course Brad as usual is making available the raw P-Cabs and the malware |
| 1:54.2 | samples. So if you want to run this yourself, here is your chance. Always refer to Brad's di Diaries when students in the intrusionation class ask for more samples |
| 2:05.6 | to really hone their skills with, and this actually makes a great sample for that. |
| 2:12.6 | And security company Veronis is describing a little bit of modified crypto coin miner that they found on a customer system. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

