meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 5th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 5 January 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. BlockInput; Windows Server RDP Patch; Malicious Telegram Installer; Web Skimmer vs. Real Estate

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 5th, 2021 edition of the Sandsenet Storm Center's

0:06.3

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:13.4

Xavier was out hunting for Malver and came across an interesting batch file that took advantage of

0:20.5

the block input API call.

0:23.6

Blog input, as you may guess by the name, blocks all user input, so it essentially locks the

0:30.0

system and does not allow the victim here to interact with the code.

0:37.0

Typically that's done as an anti-debugging feature, so this way the

0:41.9

user running the code in a debugger wouldn't be able to interact with it, but could also

0:48.1

just be to essentially complete whatever action, the particular code attempts to complete without any disruption by the user.

0:57.3

This particular script maybe the later it's a fairly simple script.

1:01.5

All it does is it basically deletes your Windows partitions.

1:06.0

So I would call it a wiper in that it basically destroys your data, and then it displays a message,

1:13.2

and doesn't really look like any ransom demand or anything like that.

1:17.2

It's really just to outright destroy the computer and tell the user that this is what happened.

1:23.6

So likely the attacker also doesn't want that process to be interrupted.

1:27.6

If you ever run into this, Xavier points out that a simple alt-control delete should give

1:32.7

you the option then to cancel.

1:35.8

And Microsoft today released the emergency update for Windows Server 2019 and Windows Server

1:41.9

2012 R2 to fix a black screen, slow sign-in, and general slowness on Windows

1:50.5

server if you're using remote desktop. The problem affects other versions of Windows

1:57.6

server as well, pretty much anything from Windows Server 2012,

2:01.6

all the way to Windows Server 2022, and other updates should be made available shortly according

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.