meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 7th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 January 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Spoofed Scans from 103/8; Iran Terror Threat; BusKill

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, January 7, 2020 edition of the Santernut Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:14.1

A participant in our Slack channel did notice a large increase in the number of source IPs scanning the internet.

0:24.5

And well, he actually noticed this based on some other systems that publish these numbers.

0:30.7

So I looked at our data and yes, we had a substantial increase on January 2nd.

0:38.0

We tracked about 270,000 IP addresses scanning the Internet, and that went up to 500,000 on January 3rd, and almost 600,000 on January 4th.

0:52.4

So it took a closer look to see what's happening here and turns out that many of

0:57.7

these sources, pretty much explaining the entire increase here, came from the 103 network. So 103 slash

1:07.8

8 was the source of these scans almost certainly spoofed. They were pretty much focusing

1:15.1

on port 22 and 23, but we didn't really see any connections in our ZH honey pots. So yes,

1:24.3

there may have been a three-way handshake. Can't really tell that based on our data,

1:29.8

but well, if someone is scanning, then why not also trying to log in? If it's something, for example,

1:35.8

like Mirai and such. Also, some of the sources came from net blocks that were not actually

1:43.1

assigned, which again confirms that these scans

1:47.3

were most likely spoofed. Not really much you have to worry about here. Kind of also interesting

1:53.9

that a doubling of the number of sources scanning the internet doesn't really make a difference

1:59.0

or excites people too much these days.

2:03.5

I don't have any great explanation for why they used 103 slash 8.

2:09.6

The only thing I sort of could come up with was that this was the last net block that

2:15.1

Ianna assigned to Appnick, so the Asia Pacific Network Information Center,

2:20.6

they received this net block in February 2011 and have since started to hand out IP addresses

2:29.4

from that net block.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.