ISC StormCast for Thursday, March 10th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 March 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, March 10th, 2020 edition of the Sands and the Storm Center's |
| 0:07.5 | Stormcast. My name is Johannes Ulrich, and I'm recording from London, England. |
| 0:14.4 | Thanks to our reader, Ron, for sending us an interesting badge file that actually implements |
| 0:20.6 | a complete info stealer. |
| 0:22.8 | Xavier wrote it up and well it shows yet again that Malvert doesn't have to be terribly |
| 0:28.6 | complicated. It does target Windows but still uses the curl utility which has been added to Windows in Windows 10. |
| 0:41.5 | And curl, of course, makes it pretty easy to download files, like in this case, an additional |
| 0:47.2 | tool to do screenshots, and then upload the results back to various websites. |
| 0:56.8 | In this case, it looks like the attacker prefers to just use the Discord API, which of course is even more difficult to detect, because Discord is |
| 1:03.9 | a very commonly used tool, so requests to that API may not necessarily raise any suspicion. |
| 1:12.3 | In addition to taking screenshots, as I mentioned, the tool will also collect details |
| 1:17.4 | from various browsers in order to exfiltrate credentials and the like to the attacker. |
| 1:24.9 | And just as a reminder, we always like interesting malware, |
| 1:28.5 | so if you have something, just pass it on. |
| 1:32.3 | Cloudflare published a blog post |
| 1:35.3 | with details regarding a new type of DDoS attack |
| 1:40.1 | that takes advantage of exposed MyCollab |
| 1:44.1 | and My Voice Business Edition collaboration systems, |
| 1:48.4 | which are produced by MyTel. |
| 1:51.7 | The root cause here is a vulnerability in the TP 240 voice over IP processing interface cards, |
| 1:57.8 | and it is, well, one of those very classical type of UDP |
| 2:02.8 | amplification attacks, but in this case with an unheard-of amplification factor of 1 to 4 billion. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

