ISC StormCast for Thursday, November 9th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 November 2023
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, November 9th, 2020, 3 edition of the Santernet Storm Center's Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.9 | Will ever wonder how fishing campaigns are tracking all the emails they're sending and calculating things like success rates and such. |
| 0:23.9 | Well, turns out they're using the same tools as commercial legitimate marketers are using. |
| 0:31.6 | Xavier came across a project file that, well, first he thought it was actually a Microsoft project file, because |
| 0:39.0 | the extension is similar. It's MMP, not MPP, as the normal Microsoft project. And the file |
| 0:48.0 | itself loaded into a tool called Gamadine, which is an email marketing tool, that then revealed the actual email being |
| 0:57.3 | used for the phishing campaign, like the HTML being embedded in the email with the respective |
| 1:04.3 | password form. There's not a new development. This is something that hackers have been doing apparently for a while. |
| 1:14.2 | And researchers from Safe Breach found an interesting bug in the Azure Automation Service |
| 1:20.4 | that allowed them to essentially run a crypto coin miner for free and also hide it from the |
| 1:27.4 | legitimate owner of the account. |
| 1:30.2 | The Azure Automation Service is able to run Python scripts, but the main goal of Azure |
| 1:36.9 | automation service is to essentially manage your cloud environment. |
| 1:41.7 | So you can do things like start and stop machines and basically organize your cloud environment. So you can do things like start and stop machines and basically organize your cloud |
| 1:47.7 | environment with little scripts without having to set up yet another machine environment |
| 1:52.8 | to actually run these scripts. |
| 1:55.1 | These scripts are run inside Docker containers. |
| 1:58.6 | And well, apparently due to a bug in Asia, the runtime of these scripts |
| 2:04.0 | was not built correctly, meaning they ran for free. Typically, probably not a big deal, |
| 2:10.4 | because if you're just sort of setting up an environment, the actual runtime for this |
| 2:16.3 | automation script is likely insignificant compared to the runtime and cost of the environment that you're setting up. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

