ISC StormCast for Thursday, May 2nd, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 May 2024
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, May 2, 2020, |
| 0:04.0 | edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.0 | Guy got a little binary that has sort of been pestering his honeypot and, well, it was uploaded via the Cowry part of the honeypot which simulates |
| 0:22.9 | open telnet and S-H server sort of run-of-the-mill Didos agent interesting kind of that |
| 0:32.2 | Ghee just uploaded it to the assembly line sandbox in order to extract some indicators of compromise. |
| 0:40.3 | You have to be really careful here with the indicators of compromise because the ones extracted |
| 0:45.9 | here are definitely not malicious sites, for example, as often 8888, the Google DNS server is one of the IP addresses. |
| 0:57.1 | This malware connects to an order to check internet connectivity. |
| 1:00.6 | It also apparently is downloading like bug reports here for Lipsc. |
| 1:05.9 | Also a very common public URL, likely just as a connectivity check. |
| 1:11.3 | So don't just blindly use these indicators of compromise. |
| 1:15.9 | They are often just used by this malware as a connectivity check, and they're using benign, |
| 1:20.8 | well-connected, and well, basically, websites that are often up and open. |
| 1:25.9 | Sort of also interesting here, and other public DNS server, they're using 114, 114, 114, 14, 14, 14. |
| 1:34.1 | So, 4 times 114. |
| 1:36.9 | That appears to be operated by a Chinese company. |
| 1:40.5 | Works well for me here, even though it does not look to be any cast. |
| 1:44.1 | This IP address, |
| 1:45.7 | according to Trace Route, does actually appear to connect to China. Maybe the author of the |
| 1:52.4 | Malver is using this in case 8888 or so is not reachable, and of course that may happen inside |
| 1:59.4 | China. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

