meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, June 2nd, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 2 June 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. LOLBAS with finger.exe; Bypassing Ransomware Protections; Firefox Patches; Edge https by default coming

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, June 2, 2021 edition of the Sandinternet Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.5

And today I'm recording from Jacksonville, Florida.

0:13.8

Renato today analyzes a recent version of the Guildmower Astoroth Malver that he came across and well it's remarkable in so far as it's

0:25.6

using a fairly old Unix utility that's also found on Windows finger.

0:31.6

Finger in the past had been used in order to check on the status of remote users who is logged into a particular

0:39.9

system and also which accounts exist. Given that the utility didn't really know any

0:48.0

off occasion and wasn't really that terribly useful, it has since pretty much been forgotten, but apparently

0:57.0

Windows still includes a fingerclined, and this latest version of Giltma is taking advantage

1:04.8

of this by using this utility to retrieve additional commands. As so many information security stories, it starts with an email that contains a SIP file as an attachment,

1:16.9

and instead of a PDF, as promised, it includes a link file that's then being used to startfinger.e.

1:26.0

And retrieve additional commands from the attackers command and control server.

1:32.3

The reply from this finger command will then be used to create a visual basic script

1:38.3

and that is being executed to then download additional malware.

1:43.3

Also taking advantage later of good old

1:46.6

Bits admin, which of course is often used to send HTTP requests and retrieve malicious

1:53.0

binaries like in this case. So overall, a pretty neat use of sort of the living off the land

1:58.9

techniques. Bits admin of course course, has been used quite often

2:02.8

for that. Finger is a little bit of a new way of starting it all off. As far as preventive or

2:10.2

detective measures go, take a look for connections to and from Port 79. That's the port used by

2:17.2

finger by default. And I believe it's safe to

2:20.9

just remove that executable from your window systems. And researchers at the University of Luxembourg

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.