ISC StormCast for Thursday, February 10th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 February 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, February 10th, 2020 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich. |
| 0:09.7 | And today I'm recording from Jacksonville, Florida. |
| 0:13.6 | Looking for some new PCAPs for Family Pack at Night. |
| 0:17.8 | Well, Brad got something interesting for you, and that's an emot head infection |
| 0:23.1 | that leads then to an install of Cobalt Strike. Brad attributes this infection to the Epoch 5 |
| 0:30.7 | bot, and it was kind of interesting is that after the initial infection, it took about five |
| 0:37.4 | hours before Cobalt strike traffic |
| 0:40.4 | started to show up. So initially, you just have the standard spam bot traffic as typical |
| 0:47.4 | for Emothead and such. It uses a number of different email ports like 587 and 465 in order to spread the malware. |
| 0:56.9 | And then later there is some Emothead command control traffic on Port 8080 as well as HTTP. |
| 1:04.3 | So 443 before the actual Cobalt strike traffic starts, which in this case uses the domain Foxoff Valley.com. |
| 1:15.0 | All the P-Caps can be downloaded from Pratt's site and more indicators of compromise you can find |
| 1:22.3 | in Pratt's diary. |
| 1:25.4 | And of course, Patch Tuesday wasn't just about Microsoft, but we had a couple other companies |
| 1:30.0 | release updates, for example, as usual, Adobe. |
| 1:34.3 | Adobe released updates for Premier Rush Illustrator, Photoshop, After Effects, and Creative Cloud |
| 1:41.7 | Desktop. |
| 1:43.6 | Illustrator has the most vulnerabilities being addressed here with |
| 1:47.4 | 13, some of them having a CVSS score of 7.8, allowing for arbitrary code execution. Photoshop, |
| 1:56.9 | after effects, and Creative Cloud desktop only have one vulnerability each, but it is also an |
| 2:05.5 | arbitrary code execution vulnerability, where Photoshop and After Effects, they assign it a CVSS score |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

