4.9 • 696 Ratings
🗓️ 28 September 2016
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, September 29th, 2016 edition of the Sands and the Storm Center's |
0:07.1 | Stormcast. My name is Johannes Orrich, and today I'm recording from Jacksonville, Florida. |
0:13.7 | Brad wrote up a diary about the Rick Exploid Kit that he has seen more recently replacing the |
0:20.8 | Neutrino Exploid Kit. If you remember, Neutrino is sort of on its exploit kit that he has seen more recently replacing the neutrino exploit kit. |
0:22.4 | If you remember, neutrino is sort of on its way out, the crew behind it is no longer in |
0:27.6 | business and the Rick Exploid kit seems to be replacing it. |
0:33.6 | In this particular case, this downloader was then used to download Ransomware, and well, nothing new here. |
0:43.3 | Locky, of course, was downloaded. |
0:45.3 | The sort of interesting part with respect to the URLs being used was that in this case, the URL was login. |
0:53.3 | Php. Haven't seen that lately, but then again, I think that has come up in the past. |
1:00.7 | From a detection point of view again, the downloader does use an artificial user agent, so you may be able to pick that out. |
1:13.0 | Also, the binary that's being downloaded is encoded so you won't really see any of the basic sort of |
1:18.2 | PE signatures here but the content type is application XMS download so |
1:25.2 | that may trigger some alarms here. |
1:28.6 | And in his latest variant, sticking sort of with its Nordic God theme, the extension of |
1:34.2 | the encrypted files is now dot Odin. |
1:38.9 | And a couple of years ago, Facebook released a tool OS query. |
1:42.8 | OS query allows you to query systems throughout an enterprise for things like which processes are running, |
1:50.8 | which ports they're listening on, what software, what files are present on the system. |
1:56.2 | So essentially all these little investigations, you usually do sort of one-on-one by remoting into a system. |
2:02.2 | You can essentially do across the entire enterprise. Problem was until now this tool was not |
2:08.3 | available for Windows. Well, it now supports Windows. They have ported it. And with that, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.