ISC StormCast for Wednesday, June 26th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 June 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, June 26th, 2019 edition of the Sansonet Stormsetters Stormcast. |
| 0:07.6 | My name is Johannes Ulrich. |
| 0:09.2 | And I'm recording from Jacksonville, Florida. |
| 0:12.2 | Interesting piece of malware from Brad today. |
| 0:18.0 | Brad came across another case of the Rick Exploid kits. Yes, we don't see a lot of |
| 0:23.4 | exploit kits these days, but Rick appears to be the one that's sort of still active and |
| 0:30.3 | left over. What's kind of almost more interesting here than the exploit kit itself is the |
| 0:36.1 | Malver that was installed by this exploit kit. |
| 0:39.6 | This malver P2B turned out to be a little bit challenging to analyze in that it refused to run |
| 0:45.8 | in virtual machine, so he actually had to run it on a physical machine. Of course, the way, if you |
| 0:52.2 | have read some of Brad's diary, the way he analyses his |
| 0:56.0 | malware is essentially by doing runtime analysis and looking at network traffic to then collect |
| 1:02.0 | indicators of compromise. |
| 1:04.1 | This of course is still pretty straightforward with a physical host, just a little bit more |
| 1:10.1 | effort in getting it all set up |
| 1:11.9 | and cleaned up after the fact. |
| 1:15.0 | This Malver then went ahead and started sending spam and it also connected back to a command |
| 1:22.9 | control server on Port 2287. |
| 1:27.3 | The domain used to spread this malware is Make Money Easy with Dot me and yes, the domain was |
| 1:35.2 | recently registered June 19th and apparently used by the Rick Exploid kit as early as June |
| 1:43.2 | 21st. |
| 1:45.9 | And if you are running servers in Amazon's cloud, traffic monitoring has always been kind |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

