meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 27th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 27 June 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. BitTorrent Sync 2.0 Forensics;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 27th, 2017 edition of the Santernut Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and today I'm recording from Columbia, Maryland.

0:12.5

Big Torrent, of course, often plays a role in forensics investigation, as it is kind of a neat tool in order to exfiltrate data.

0:21.6

Now, today we have a nice guest diary by Ali Dekantana

0:26.6

about one particular implementation, BitTorrent Sync,

0:30.6

which also is now known as Resilio.

0:33.6

In his blog post, Ali is going over some of the artifacts that he discovered on systems that did run BitTorrent sync version 2.0.

0:45.3

Now, this is the first part of a multi-part post that he prepared that goes over different aspects of the forensic artifacts that you are finding

0:57.0

as residual evidence for BitTorrent Sync 2. The next blog actually hopefully will get to publish this

1:06.0

maybe later this week or early next week will cover some of the log files left behind.

1:12.9

I think it was last week that South Korean web hosting company Naya went public about

1:19.0

paying $1 million in order to avert DDoS attack.

1:25.3

Now, sadly and somewhat predictable, this has started a new wave of ransom

1:32.1

DDoS attacks against a number of banks in South Korea. Now, the name mentioned with these

1:40.2

ransom demands is the Armada Collective. Armada Collective was quite active in the

1:47.0

ransom DDoS scheme about two years ago or so. I considered the crew pretty much defunct. Since then,

1:55.0

there were a lot of fake ransom demands like the ones I talked about on Friday and yesterday.

2:02.5

So not sure if this is just a new group that sort of took over that name or if it's again

2:08.9

just fake ransom demands.

2:12.6

We'll find out, I guess, and see whether or not these banks will actually be attacked.

2:19.3

The group did demand in the order of $300,000 from these banks in order to avert the DDoS attack.

2:28.3

Banks, of course, typically have quite strong anti-DDoS defenses given past history, where banks were always kind of at the top

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.