meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 10th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 November 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. PS Ransomware; iOS/MacOS XML Patches; Lenovo UEFI Patch;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, November 10th, 2020 edition of the Science and Storm Center's Stormcast.

0:08.6

My name is Johannes Ulrich.

0:10.2

And today I'm recording from Jacksonville, Florida.

0:15.1

Not all, ransomware is super sophisticated Xavier ran into a ransomware sample that actually does just with Visual Basic for Application and PowerShell.

0:28.2

Now, the Visual Basic for Application script is just used to create the PowerShell script, and well, then it goes and encrypts more details in the diary that Xavier published,

0:42.2

but just in short, it uses Ncrock.io, the cloud service that's used sort of to test APIs

0:49.8

as a command control server, which really means that all requests are being forwarded to another

0:56.5

server that of course we don't know about. Also, this particular command control server, as well

1:03.3

as the Onion site mentioned in the ransomware node, are no longer available. It does exfiltrate the key directly via NGROC,

1:13.6

so that's sort of how it manages keys,

1:17.6

and then it also has an interesting kind of quirk in

1:21.4

that it does not run on a system

1:23.7

that has a directory called Oracle Kit.

1:29.0

This may just be to sort of prevent multiple infections of the same system.

1:35.4

Now, since it's so simple, it doesn't expeliorate any data.

1:38.3

However, it claims it does so.

1:41.0

And of course, that's also often happening with sort of the lower end ransom

1:45.1

where it makes claims that are just not true.

1:49.3

In some cases, actually, even where it claims that the files are encrypted, even though

1:53.2

they're not actually encrypted, but just renamed.

1:57.6

Now, in this case, your files are encrypted, and also any backups, shadow copies,

2:02.3

and such are deleted as well. And Apple today released two surprise updates, not that they

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.