ISC StormCast for Thursday, July 27th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 July 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, July 27th, 2003 edition of the Sands and its Stormsend, Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.2 | Personally, I have often stated I'm not a big fan of sort of IP address block list. There is a lot of, well, a suspect sort of |
| 0:23.3 | evidence that's sometimes being used to create these block lists. But well known that many good |
| 0:29.9 | guys, but also bad guys are blocking traffic to specific IP addresses. Xavier looked at the specific malware sample |
| 0:39.3 | to figure out, well, the particular IP addresses |
| 0:42.9 | that are being blocked here, |
| 0:45.1 | what they have in common, |
| 0:46.8 | and how they are actually being used. |
| 0:51.0 | Turns out a lot of cloud providers |
| 0:52.8 | are being listed here in this particular |
| 0:55.4 | sample. Could be that attackers are suspecting that maybe there are some sort of analysis |
| 1:01.5 | systems at these IP addresses, or maybe just that they don't consider these particular cloud |
| 1:07.7 | providers valid or worthwhile targets for the particular malware, |
| 1:12.8 | given that malware often does target client systems, |
| 1:16.8 | so they're less likely going to be located in these cloud environments. |
| 1:22.1 | Overall, I think same applies to the back guys as to the good guys, |
| 1:26.8 | that sometimes these block lists are not necessarily |
| 1:31.0 | built out of solid and robust evidence, but more or less some anecdotal evidence where |
| 1:38.4 | maybe a particular attacker had a bad experience with a particular IP address. |
| 1:45.1 | End-to-end encryption for messaging systems has been sort of a hot topic these last few years, |
| 1:51.0 | like with various offerings from companies like Signal. |
| 1:55.5 | Google now stated that it will implement end-to-end encryption, but it will actually be based on an open standard. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

