meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 10th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 March 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. batch infostealer; Mitel DDoS; Pro Ukrainian Hacking Tools Malware; Hack .ru Govt Sites

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 10th, 2020 edition of the Sands and the Storm Center's

0:07.5

Stormcast. My name is Johannes Ulrich, and I'm recording from London, England.

0:14.4

Thanks to our reader, Ron, for sending us an interesting badge file that actually implements

0:20.6

a complete info stealer.

0:22.8

Xavier wrote it up and well it shows yet again that Malvert doesn't have to be terribly

0:28.6

complicated. It does target Windows but still uses the curl utility which has been added to Windows in Windows 10.

0:41.5

And curl, of course, makes it pretty easy to download files, like in this case, an additional

0:47.2

tool to do screenshots, and then upload the results back to various websites.

0:56.8

In this case, it looks like the attacker prefers to just use the Discord API, which of course is even more difficult to detect, because Discord is

1:03.9

a very commonly used tool, so requests to that API may not necessarily raise any suspicion.

1:12.3

In addition to taking screenshots, as I mentioned, the tool will also collect details

1:17.4

from various browsers in order to exfiltrate credentials and the like to the attacker.

1:24.9

And just as a reminder, we always like interesting malware,

1:28.5

so if you have something, just pass it on.

1:32.3

Cloudflare published a blog post

1:35.3

with details regarding a new type of DDoS attack

1:40.1

that takes advantage of exposed MyCollab

1:44.1

and My Voice Business Edition collaboration systems,

1:48.4

which are produced by MyTel.

1:51.7

The root cause here is a vulnerability in the TP 240 voice over IP processing interface cards,

1:57.8

and it is, well, one of those very classical type of UDP

2:02.8

amplification attacks, but in this case with an unheard-of amplification factor of 1 to 4 billion.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.