meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 30th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 30 March 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Better Phishing E-Mails; Crusader Adware; VMWare Patch

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 30th, 2017 edition of the Santanet Storm Center's Stormcast.

0:07.6

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:12.6

Xavier today had an interesting example of one of the better-done fishing emails.

0:18.1

Of course, the problem sometimes with fishing exercises or

0:21.6

when we are showing fishing messages to users is that they're almost too obvious bad

0:29.0

in his case well he actually received a pretty good one that you certainly could

0:34.5

fall for it was one of those package delivery failed messages that didn't have

0:41.7

any typos. It looked just like the real thing. And of course, well, like many people, he orders a lot

0:47.6

of stuff online. So he did expect some deliveries. It's always good to throw in one of these better emails in order to really get

0:59.1

users ready for what they should expect from some of the more sophisticated fishing scams.

1:07.2

Encapsalize providing us with an update what's going on with the Merai botnet these days.

1:14.0

Now, Marai, of course, it's still around, it's still strong, there are still hundreds of thousands of hosts

1:19.4

that are in some form connected to one version or the other of these botnets.

1:27.4

And in Encapsulize's case, one part of that Myri Botnet was used to attack US College.

1:35.6

Sort of interesting here that they actually used a Layer 7 attack, which means they used

1:40.2

valid HTTP requests.

1:42.7

Now, overall, that's not really new for Mirai. Mirai had that

1:46.6

capability from the beginning and we have actually seen some denial of service attacks like

1:52.3

this from Internet of Things botnets before they were called Mirai. Sort of different here is that

2:00.8

the requests vary quite a bit, making, filtering even more

2:05.2

difficult. Most of these simple, in-in-of-of-things, botnets, if they attacked you, all of them

2:12.3

sent the same request. Here, user-achshund alike keeps changing. And then, then of course and that's again typical

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.