ISC StormCast for Thursday, May 9th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, May 9th, 2019 edition of the San Center Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and today I'm quoting from San Diego, California. |
| 0:13.1 | In case you're ever running out of interesting Malware to analyze, Pratt has a new game for you email roulette that he's playing using virus totals threat |
| 0:23.6 | intelligence service. With the service, he went through recent submissions and found an |
| 0:29.7 | interesting email in Korean debt that then included ransomware. Brad also shows how to actually get the email message that belongs to the particular attachment |
| 0:42.7 | that was flagged by these antivirus engines. |
| 0:46.9 | The malware itself turned out to be yet another version of Gant Crab, |
| 0:52.1 | which is sort of one of the big ransomer families going around today. |
| 0:57.0 | And ESET security came across an interesting, stealthy backdoor in Microsoft Exchange servers |
| 1:06.0 | that they're calling Light Neuron. Now the trick here is that this software installs itself |
| 1:14.3 | as a mail transport agent, so it really is a module in that way in Microsoft Exchange running |
| 1:22.1 | as a system. Once installed as a mail transport agent, this particular module has access to all emails. |
| 1:30.3 | It's also able to send emails via the Exchange Server, and this is also then used as a command and control channel. |
| 1:39.3 | In order to send a command to Light Neurone, the attacker has to send, for example, a PDF or a JPEC that |
| 1:48.7 | will include instructions for LightNoron that it will then execute. So for a Mail Server, this |
| 1:55.6 | is way more stealthy than anything else like HTTP requests or DNS and the like, because, well, you would expect |
| 2:03.7 | a mail server to receive and send email. |
| 2:07.7 | And the emails themselves, of course, look just like any other email, just that they have |
| 2:13.3 | this JPEC or PDF attachment, which again isn't in itself all that suspicious. |
| 2:19.5 | And to further evade detection, the light neuron is also quite selective in what emails |
| 2:26.6 | it will actually crap and forward. Apparently, this particular malware has been going |
| 2:32.8 | around for about four years now |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

