meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, December 14th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 14 December 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. GUI Python Malware; Adobe Updates; TeamCity Exploited; Sophos Patches EOL Devices

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, December 14th, 2020, 3 edition of the Sandton and the Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich, and today I'm recording from Washington, D.C.

0:15.1

Today we have a diary by Xavier looking into an interesting Python script that Xavier came across.

0:22.0

One thing that distinguishes this particular Python script from other Malver

0:26.4

is that it actually shows up on the screen with a GUI,

0:31.1

doesn't just run in the background, and attempts to remain unnoticed.

0:36.4

The Malver does call itself ProMine Checker.

0:39.8

ProMine is the name of developer tool and debugging tool,

0:46.0

so maybe it attempts to claim to be related to that.

0:48.7

It accepts some files and then offers a check button,

0:53.1

which doesn't really do anything, no matter whether you add files and then offers a check button, which doesn't really do anything, no matter whether

0:55.6

you add files and don't add files, whenever you click the check button, well, all you see

1:02.1

is an error message.

1:03.4

So a user may be inclined to believe that the software just isn't working right and

1:08.7

uninstalling it.

1:10.2

Well, that's already too late.

1:13.8

As soon as you run the software, it will actually collect credentials in the background and

1:20.3

then exfiltrate it.

1:21.7

Also kind of typical behavior for what we often see in Malware that targets developers.

1:28.3

It looks for password files, Discord credentials,

1:32.3

Roblox credentials, sort of typical things that you may find

1:36.3

on developer workstations, and then it exfiltrates them via a webbook.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.