ISC StormCast for Thursday, November 21st 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 November 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, November 21st, 2019 edition of the Sansanet Storm Center's Stormcast. |
| 0:08.3 | My name is Johannes Ulrich, and today I'm recording from Riyadh, Saudi Arabia. |
| 0:14.1 | Brad did an update on what he's currently seeing with the Hankytore malware. |
| 0:18.9 | Now, this malware is currently being distributed by these |
| 0:23.5 | docu-sign emails. If you probably have all seen them in the past, they're often caught by |
| 0:29.9 | spam filters, and so not a huge threat, but apparently it's still successful enough for the bad guys |
| 0:35.9 | to continue to use them. |
| 0:38.8 | Hank Gator, of course, is essentially just the first stage, the downloader that will then |
| 0:43.5 | install additional malware on an infected host. |
| 0:47.3 | According to Brad's recent observations, this is often than the pony malware, which is essentially an information stealer, so collecting |
| 0:56.7 | usernames and passwords from your system. As always, Brad is providing indicators of compromise, |
| 1:04.5 | as well as traffic captures of an infected machine, so you can reproduce some of the work yourself. |
| 1:14.1 | And the ERP security company on NAPSIS is warning that about half of the companies that are |
| 1:22.2 | using Oracle's e-business suite have not yet patched vulnerabilities for which updates were made available in April |
| 1:30.6 | this year and actually as far back as April last year. Ennapsis calls these vulnerabilities |
| 1:37.6 | together payday vulnerabilities in part because of the potential financial impacts that exploiting these vulnerabilities may have. |
| 1:49.0 | Exploiting these vulnerabilities does not require authentication and could, for example, |
| 1:54.7 | be used to change approved electronic file transfers to send payments to the attacker's bank account, for example, |
| 2:04.7 | and apparently exploitation does not leave a trace according to Onypsis. |
| 2:11.1 | Now, Anapsis is a company that, of course, makes its living, protecting organizations |
| 2:16.0 | from these type of vulnerabilities. It should |
| 2:18.8 | be noted that they are not seeing any exploitation in the wild, but given the age of these |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

