4.9 • 696 Ratings
🗓️ 13 April 2021
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, April 13th, 2021 edition of the Sandstone Storms, Stormcast. |
0:08.1 | My name is Johannes Ulrich. |
0:09.7 | And today I'm recording from Jacksonville, Florida. |
0:14.0 | Did he and his post today took apart a piece of malware, actually the traffic collected from that Malver that Brad posted to his collection |
0:24.7 | of Malver traffic. The interesting thing about this particular sample was that it included |
0:31.7 | Cobalt strike traffic that was not encrypted. Usually Cobalt Strike traffic should be encrypted with AS, but well, if you're using the |
0:43.3 | trial version as this is what may have happened here, the traffic is not encrypted, and |
0:49.3 | it gives an easy simple insight into how the Cobalt Strike Beacon and Command Control traffic |
0:57.0 | works. So D.D.A walks you through some of that and also how to decode some of this traffic. |
1:05.0 | And given Cobalt Strikes capabilities, it's very likely that a less sophisticated attack, |
1:11.9 | or it doesn't want to pay the money to purchase Cobalt Strike or find a leaked version of the software, |
1:19.9 | will use the unencrypted trial version because, well, better to have an unencrypted command control channel than no command control |
1:29.4 | channel at all. |
1:31.9 | And Cisco published an interesting field notice. |
1:34.5 | Now, field notices are not security vulnerabilities, but since it does affect the ASA |
1:41.1 | 5506 series security appliances, I consider it sort of security relevant. The problem here is |
1:48.1 | that after 3.2 years of uptime, these appliances will fail due to an SSD disk bug. The problem |
1:59.0 | is actually 100 million seconds, so 3.2 years translates roughly 200 million |
2:06.3 | seconds. Once you reach that many seconds of uptime, the SSD will fail. This is not just for |
2:14.4 | these Cisco uplines. Similar bugs were reported, for example, for some servers |
2:20.2 | that use the same type of SSD, |
2:23.3 | and firmware update to the SSD will fix it. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.