4.9 • 696 Ratings
🗓️ 24 June 2020
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, June 24th, 2020 edition of the Sandsenert Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:12.8 | Well, today we got an interesting diary thanks to one of our Sands EDU graduate students, Karim, he rode up traffic going to the Cyberbunker |
0:26.2 | Network. |
0:27.5 | Now I'm planning on having him on the show on Friday, but a little bit ahead of that |
0:33.7 | about what he found. |
0:35.6 | First of all, Cyberunker is, is well about as real of a bulletproof |
0:40.2 | hosting provider as there was in that cyber bunker operated out of an actual nuclear bunker. |
0:48.7 | They purchased that in Germany was one of the leftover Cold War NATO bunkers that they moved their servers into, |
0:57.9 | and well they hosted a number of criminal websites and the like out of that bunker. |
1:05.0 | Now late last year around September, the entire operation was raided, and at the time, of course, the servers were dismantled, |
1:13.2 | but we now got a chance to actually have the IP address space that CyberBunker used |
1:19.7 | assigned to one of our Honeypots. So based on the traffic that our Honeypots received, |
1:25.8 | we were able to kind of deduct a little bit how |
1:28.2 | cyber bunker operated. |
1:30.4 | Cyper bunker didn't necessarily run these different websites themselves. |
1:34.9 | They sort of operated like a co-location hosting provider. |
1:40.5 | What I found interesting was, well, first of all, there were still a couple of botnets reaching out to what appear to be command control servers that were co-located with Cyberunker. |
1:53.3 | But almost more interesting, I found ad traffic that would point back to various websites within Cyberpunker. |
2:02.0 | So these ads as part of the links pointing to the cyberpunker websites, |
2:08.2 | which of course were now defunct, we didn't have the content of the sites, |
2:12.2 | but keywords added to these referral links kind of told us what these websites were about. Now, the particular |
2:20.2 | ad network being used here, get my ads.com appears to be also a little bit shade in the sense |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.