meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 25th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 25 August 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Monster Libra; Tox Coinminers; Carbon Black Blue Screen; GitLab Vulnerability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, August 25th, 2022 edition of the Sands Internet Stormsanders Stormcast.

0:09.6

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:16.0

Brad is on a role with his second Malware analysis diary in as many weeks.

0:22.8

This time Brad grabbed a Monster Leipra sample.

0:26.9

Now, Monster Leipra is also known as TA551 or Shattac.

0:32.2

And again, as so often, the malware starts out with a Word document and of course tricks the user

0:40.1

into enabling macros.

0:43.2

Yet another reason why it's so important that Microsoft is clamping down on these macros.

0:50.9

This initial macro downloads a DLL file that then installs Iced ID, which in the end pulls either Dark VNC or Cobalt Strike.

1:02.4

That's a very typical combination that we have seen in the past.

1:05.8

Sometimes in the past we have seen, for example, dark VNC being installed more on sort of standalone systems

1:11.6

and then Cobalt Strike more on active directory controlled systems. Packet captures,

1:18.0

indicators of compromise, and more are as usually included in Brad's write-up. And talking

1:26.5

about malware and traffic analysis, security company Upticks has published analysis

1:33.4

showing how what they think is crypto miners, even though they haven't really observed

1:37.8

the crypto miner part here yet, but Malware taking advantage of the talks peer-to-peer protocol for command control.

1:46.6

So not Tor with R, instead, talks with an X in the end.

1:51.4

And TOX is well, well-suited for this kind of command control.

1:56.1

It's a serverless protocol.

1:57.7

You have seen sort of these peer-to-peer protocols pop up from time to time.

2:02.6

Machines are only talking to each other.

2:05.0

There is no sort of central server infrastructure that could be taken down.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.