ISC StormCast for Thursday, June 7th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 June 2018
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, June 7th, 2018 edition of the Santernet StormSandr's Stormcast. My name is Johannes Ulrich, and I'm recording from Augusta, Georgia. |
| 0:12.1 | Cisco released an update to a VPN filter. Turns out that more devices than originally thought were infected by this particular malware. |
| 0:23.6 | They added a number of Aces, Huawei, Dealing, ubiquity, Yupil |
| 0:29.6 | and also additional micro-tick and CTE devices to the list of devices that VPN filter infected. |
| 0:38.3 | Now for these manufacturers it's only very specific devices that are listed. |
| 0:44.3 | For example, for Obiquity, it's their nanopridge and their power bridge access points. |
| 0:51.3 | It's not the, I think, more popular Unify access points, for example. However, |
| 0:57.7 | for example, for Unify, a lot of their devices ship with simple and well-known default |
| 1:04.0 | passwords that the user has to change. So they have long been a big target of sort of these |
| 1:10.2 | widespread scans for weak passwords. Cisco also has been a big sort of these widespread scans for weak passwords. |
| 1:14.6 | Cisco also discovered two new stage three plugins. |
| 1:18.6 | The first one is able to intercept HTTP and HTTP traffic and then modified to, for example, inject malicious software. |
| 1:28.3 | Cisco pronounces this one Esler, it's spelled SSL-E-R, then a second plug-in that can be used to |
| 1:36.3 | override device firmer. |
| 1:39.3 | And talking about modems and routers, they also appear to be at the focus of the Prowley Botnet. |
| 1:45.5 | This is a botnet that's said to have infected about 40,000 devices and web server. |
| 1:52.7 | It doesn't just go after modems and such. |
| 1:56.8 | It also goes after triple, WordPress and Jumla websites with very well-known vulnerabilities. |
| 2:05.2 | Now, this particular botnet has more than one trick up its sleeve. |
| 2:09.9 | It does do crypto coin mining, but first actually checks if the system it's infecting is suitable for crypto coin mining. |
| 2:18.9 | It also defaces websites in order to then host other malicious code and the like. |
| 2:26.3 | And yes, it does launch an SSH scanner that looks for additional victims. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

