meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 22nd, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 22 December 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Undetectes PS Droppers; Apache Patches; Auerswald PBX Backdoor; Garrett Metal Detectors

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 22nd, 2021 edition of the Sandcent Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.5

Xavier today looked at more power shell back doors that are not detected by any of the virus scanners in virus total right now.

0:25.3

Now, virus total, of course, only does sort of a static analysis without running any of the code.

0:32.1

But it yet again shows how simple application techniques, like in this case just replacing a couple strings

0:39.7

and then basics for decoding the remainder does result in Malver that antivirus has

0:48.9

difficulties detecting. The Malver itself once unpacked and analyzed turned out to be an information

0:56.8

stealer, it looks at a number of different software packages and then exfiltrates any data

1:04.7

it may find. While not really a crypto miner, the malware does appear to call itself gold miner and does connect to a host

1:13.9

at Mywire.org in order to establish a command and control connection.

1:21.6

And we've got updates from Apache, no not for Log 4J, but for the Apache HTTP server,

1:27.2

and that brings it up to version 2452 which fixes two vulnerabilities.

1:33.8

One is a possible null dereference or server-side request forgery in the forward proxy configuration.

1:42.6

That actually is the one that I would almost rate more importantly, even though it's

1:47.3

really only moderate.

1:48.8

The other one is rated high.

1:50.8

It's a buffer overflow when parsing multi-part content, but it only affects mod

1:57.2

Lua, which I don't really see that terribly often.

2:01.2

That's why I actually would consider the moderate vulnerability more important here than the

2:07.6

high one.

2:08.5

Nevertheless, none of this sort of warrants an emergency update, in my opinion, wait for

2:14.5

your Linux distribution to come up with updated packages.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.