4.9 • 696 Ratings
🗓️ 19 September 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, September 19th, 2020, |
0:04.6 | edition of the Sansanet Storm Center's Stormcast. |
0:08.5 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:14.9 | VPNs have been in the crosshairs of attackers for quite a while now. |
0:19.7 | Lots of ransomware is getting deployed via weak VPN access passwords. |
0:26.5 | And well, today I noticed in one of our larger honeypot installs that there is a group of |
0:34.5 | IP addresses looking for four very specific IP addresses |
0:39.8 | that are all VPN related. |
0:42.6 | Now, two of them are fairly generic, |
0:44.5 | so it wasn't really able to pin down a particular VPN, |
0:49.2 | even though the fourth one here looks like it's probably |
0:51.9 | some kind of net scalar remote access product you're |
0:54.6 | looking for here. There is Global Protect, the Palo Alto VPN, that's sort of on the target list |
1:02.0 | here, as well as Pulse Connect, which of course is another often targeted VPN product. |
1:10.2 | What this really means is that, well, if you have a VPN exposed to the world, it will get |
1:18.3 | discovered. |
1:19.5 | This particular scan was quite aggressive and probably made it through the internet by now. |
1:27.1 | All the scans for this particular group did originate from a particular slash 24 that's |
1:34.2 | geolocated in Russia. |
1:36.7 | Wouldn't really make too much of the fact that it's geolocated in Russia. |
1:41.1 | This happens to be sort of an average average low-cost virtual machine, virtual server |
1:47.2 | provider. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.