4.9 • 696 Ratings
🗓️ 16 September 2021
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, September 16th, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. |
0:09.8 | And I'm recording from Jacksonville, Florida. Brad today dropped one of his usual diaries, including packet captures and everything you need to reconstruct and follow the lessons that Brad is teaching you here. |
0:26.4 | And in this case, Brad is illustrating the latest Hankitor campaign. |
0:32.1 | Now, Hankitore is essentially a malware delivery mechanism. |
0:37.4 | In the past, it often has used Google Cloud |
0:41.1 | features in order to deliver its malware, like, for example, docs.com, or feedproxy.com. Of course, |
0:50.9 | pretty much no cloud service is immune from being abused to deliver malicious content. |
0:57.8 | It looks like Hank Gator now set its sides at the Microsoft OneDrive service in order to spread its malicious Word documents. |
1:08.2 | With that, it also changed strategies a little bit. In the past, the document was |
1:13.7 | usually served using a base 64 encoded script. But in this most recent hand guitar version, |
1:24.6 | it essentially just points to a Microsoft OneDrive URL. |
1:30.3 | Of course, malware campaigns always try to mix up things a little bit as detection is catching |
1:34.8 | up. Also, as detection of these cloud providers may make the 12 time that the malware |
1:42.6 | achieves inside these clouds a little bit too short to be fully |
1:46.8 | effective, so that's when they may, for example, switch to a different cloud in order to |
1:53.8 | gain the full effect of the samples they are preparing. |
1:59.1 | So remember yesterday when I talked about Microsoft's patch Tuesday and I pointed out that Microsoft did patch critical vulnerabilities in the open management infrastructure or OMI. |
2:12.2 | And I wasn't really sure how widely this particular product was used. |
2:16.9 | It's an open product that Microsoft also published on GitHub. |
2:22.8 | Well, it turns out that this is actually a huge problem if you are running a Linux virtual |
2:28.3 | machine on Microsoft's Azure Cloud Service. |
2:32.2 | As many cloud services, if you are running a virtual machine, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.