ISC StormCast for Thursday, June 1st 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 June 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, June 1st, 2017 edition of the Sansadet Storm Center's Stormcast. |
| 0:07.3 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.8 | Pascal today published the second part to his diary about the ACH method and applied it to the Wanna Cry outbreak. |
| 0:22.8 | Now, he took what Digital Shadows did last week and expanded it with a couple of additional |
| 0:29.3 | hypotheses. |
| 0:30.9 | Essentially, his outcome isn't all that different from what they found. |
| 0:35.6 | Lazarus Group, state actor, sophisticated financial actor, |
| 0:40.2 | all of that actually ranks quite low. He also added a couple of other criteria and is sharing |
| 0:48.3 | his spreadsheet so you can play with this a little bit yourself and see what results you come up with. |
| 0:56.1 | And security company Crypto's Logic did publish some results from the WannaCry sinkhole that they apparently ran. |
| 1:05.2 | Turns out that the domain, the Kill Switch domain, was actually redirected to a sinkhole that they operate |
| 1:12.1 | and they published now some data from it. They detected a total of around 700,000 unique |
| 1:19.8 | IP addresses hitting their sinkhole. Now, how that correlates with the number of actually |
| 1:26.2 | infected hosts is always a tricky |
| 1:28.6 | undertaking, but the actual number is likely larger because some of these hosts, of course, |
| 1:35.0 | were behind Nat and showed up as one IP address. |
| 1:38.7 | The Cryptos research goes a little bit into details on that. |
| 1:43.0 | The other thing that they show very obviously here |
| 1:46.2 | and was sort of known before that China was hit quite hard by Wanna Cry more than other |
| 1:53.6 | countries. Actually, it looks like they have about six times the infection rate of the US and |
| 2:00.6 | Russia, in part that has been interpreted to Chinese |
| 2:04.6 | systems being usually less often patched. And that again has been interpreted to a lot of Chinese |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

