ISC StormCast for Thursday, September 17th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 September 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, September 17th, 2020 edition of the Sansonet Storm Center's |
| 0:07.1 | Stormcast. My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:13.5 | This week we actually came across a somewhat different sample of Mariah. I forgot where we actually got it from, I think was one |
| 0:22.3 | of our honeypots or a reader I think may have sent it from a honeypot. But essentially at first, |
| 0:29.8 | it looks like any other Marai sample scans very aggressively for 423 telnet and then tries the standard brute forcing that Mirai is kind of |
| 0:41.9 | known for. |
| 0:42.9 | What surprised me was that it included a string in the binary that pointed to Amanda backup. |
| 0:51.1 | Amanda short for the Advanced Maryland Automatic Network Disc Archiver, is a fairly popular |
| 1:00.9 | multi-platform backup open source product, usually seen more in the Unix world than the Windows |
| 1:08.5 | world, but there is a Windows client available. |
| 1:11.9 | And while it has been around for a while. |
| 1:15.0 | Actually, at first I thought the string referred Manda 2.3. |
| 1:20.7 | That version was released, I believe, in 1998. |
| 1:25.3 | But this is sort of a very generic string that's really just checking what version the Amanda |
| 1:32.2 | Klein is running that the scanner would connect to. |
| 1:37.5 | Now this looks still like it's sort of work in progress for this particular Mariah variant. |
| 1:43.5 | I haven't been able to trigger this particular |
| 1:46.7 | activity. And now what's also a little bit different from the classic Mirai is there is a little |
| 1:51.6 | command control channel going on here. Didn't receive any meaningful content while I was |
| 1:58.5 | running it in my lab, but potentially this could be remote-activated, |
| 2:05.3 | have to take a closer look at the binary. Backup software, of course, is a gold mine for an attacker |
| 2:11.1 | and, well, weak passwords. If they work against Telnet, why not try them out against the backup system as well? |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

