meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 17th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 17 March 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Qakbot News; Gh0stCringe via MySQL/MSSQL; dompdf 0 day; openssl dos; pfsense update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 17th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.1

Well, today we got an update from Brad about QuackBot.

0:17.6

QuackBot has been around for quite a while.

0:20.4

This is a sample that Brad captured this

0:24.4

week and it follows the standard pattern. It arrives as an email with a link. You click on the link,

0:32.9

you download a SIP file and that then extracts to an Excel file with macros, which of course

0:40.4

the user will then enable. That macro will download the Quackbot DLL files and then there is

0:48.0

command control traffic which was sort of interesting here that there wasn't just the standard

0:53.7

quagbot command control traffic,

0:56.8

but there was also Cobalt Strike, which has become somewhat common, of course, these last couple

1:03.5

years, and then there was VNC, VNC, probably sort of for convenience and also ease of use.

1:13.2

Interesting that it took 17 hours actually for the command control traffic to show up.

1:20.2

This maybe because it was done more interactively like VNC, so pretty much had to wait for the attacker to wake up and start

1:31.2

actually connecting back to the infected system. But also sometimes these delays show up in order

1:37.7

to avoid detection in sandboxes. As always, Pratt is making available the P-Caps and all the indicators of compromise,

1:47.9

in particular the P-Caps, of course, are a great resource to learn how to take apart the traffic

1:55.3

generated by this type of malware. And Unlop has a write-up about Ghost Grinch.

2:04.1

That's a remote access tool that's sort of derived from the Ghost Ratt according to

2:08.7

Unlab and going back to December 2018.

2:13.2

What's sort of new here is that it's now using vulnerable Microsoft SQL and MySQL servers

2:21.0

in order to install additional tools like Ghost Grinch, the remote access tools.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.