meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 12th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 June 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Lokibot Update; ETH JSON RPC Theft; Cryto Currency Miners Hiding; FBI BEC Arrest

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 12th, 2018 edition of the Sansonet Stormsand Stormcast.

0:07.0

My name is Johannes Ulrich and I am recording from Jacksonville, Florida.

0:12.0

Today we got a reminder from Brand not to forget about Lockybot.

0:17.0

Lockybot was big last year, sort of October last year, and it typically spread, well,

0:23.6

like most of this malware via malicious emails, in particular sort of these shipping notifications

0:30.1

and the like.

0:30.9

I guess people got better in identifying these types of emails, maybe also anti-malware got better in eliminating this particular

0:40.1

threat, so we haven't heard about it in a while, but as Brad points out, it's still very much alive

0:47.3

and going around infecting people who don't have these precautions in place. And talking about the updates 360 NetLab, also known as Chihu 360, gives us an update on some of these JSON RPC scans looking for vulnerable Ethereum wallets.

1:08.0

These scans typically hit port 8,545 and we have written about this in the past as well,

1:15.3

but what NetLab 360 now did is that they actually followed up with some of these scans

1:22.6

and looked at some of the wallet addresses that have been doing this for a while.

1:29.3

Well, amazingly, they got $20 million worth of Ethereum now in their wallet that was used

1:36.9

in these random scans.

1:39.1

And talking about cryptocurrencies, cryptocurrency miners are still a big thing.

1:43.8

They're still being installed using any number of vulnerabilities.

1:48.0

Now, it has so far been pretty simple to spot these miners because they take up a lot of CPU time.

1:57.0

Now, a more recent miner that was now discovered is a little bit more careful.

2:03.4

Whenever a user starts task manager, process explorer, process hacker, essentially tools

2:09.7

to review the CPU usage, this miner will terminate.

2:14.4

It will also terminate if the user does start any number of popular games that

2:21.2

will also require a lot of CPU. So in order to not get detected, it will then terminate to

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.