ISC StormCast for Wednesday, June 28th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 June 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, June 28, 2017 edition of the Sands and the Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich and the day I'm recording from Columbia, Maryland. |
| 0:13.0 | Well, you probably heard by now, but there is yet another ransomware strain making the rounds, |
| 0:20.0 | taking advantage of the exploits leaked from |
| 0:23.6 | the NSA, known as Eternal Blue and Eternal Romance. |
| 0:28.6 | Now what distinguishes this latest version from WannaCry is most of all how it enters the network. |
| 0:36.6 | WannaCry really relied on scanning the internet for exposed SMB version one hosts. |
| 0:44.3 | This latest version apparently got started initially via a malicious upgrade. |
| 0:49.3 | A Ukrainian company that makes accounting software apparently got preached and then pushed out the |
| 0:57.5 | malware to its customers in the form of an automatic update. Somewhat ironic that this malware, |
| 1:05.3 | which still relies a lot on unpatched systems, did get started with a patch, but this particular software company |
| 1:14.5 | actually had this happen before. |
| 1:17.1 | Apparently back in May, another strain of ransomware was pushed by this company via its |
| 1:24.1 | update servers. |
| 1:25.6 | Now, of course, once the Malvery entered a particular network, it did use |
| 1:30.3 | the Eternal Plu and Eternal Romance exploits to spread. There's also evidence that it does use |
| 1:36.8 | WMIC, so essentially if it can get a hold of unprotected shares, it will try to copy itself. |
| 1:45.0 | Another difference to Eternal Blue here is how the encryption works. |
| 1:49.3 | Eternal Blue did encrypt individual files. |
| 1:52.5 | This particular ransomware does actually reboot the system and then attempt to encrypt |
| 1:58.4 | the entire disk. |
| 2:00.2 | So the system will reboot and then you'll see a check disk message. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

