ISC StormCast for Wednesday, May 26th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 May 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 26, 2021 edition of the Sansonet Storms owners. |
| 0:07.5 | Stormcast, my name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.8 | Today's diary actually was made possible by a reader Earl who discovered some interesting domains within an IP address block, 95-181-152-12 |
| 0:26.6 | that is hosted by MSK hosting, a hosting company out of St. Petersburg. |
| 0:34.5 | Now, Earl's observation is actually interesting from a couple of perspective. |
| 0:38.5 | First of all, I didn't even realize that Hurricane Electric has a nice sort of passive reverse |
| 0:45.1 | DNS lookup tool. You can enter an IP address or a network, like in this case, and it will |
| 0:51.8 | return a list of host names that point or used to point |
| 0:56.1 | to these particular IP addresses. Usually, Hurricane Electric is more known for its nice |
| 1:02.2 | free IP6 tunnel service and sort of BGP information that they usually provide, and this is, I guess, |
| 1:09.5 | something they recently added to their BGP toolkit. |
| 1:13.6 | So all noted that a number of domains that point to this particular IP address range are impersonating |
| 1:21.8 | well-known brands, like, for example, Instagram. One of the domains, for example, |
| 1:27.8 | Instagram-TemSupport.com. |
| 1:31.3 | Or Instagram account verification page.com, |
| 1:34.7 | which just shouts out the phishing page. |
| 1:38.4 | But, of course, these are the kind of host names |
| 1:40.6 | and domains that are being used for phishing Instagram users. |
| 1:45.9 | Now, Hurricane Electric's BGP pages also make it easy then to figure out what other networks |
| 1:52.1 | are hosted by MSK hosting and they're all in the same AS. |
| 1:58.5 | Actually, it's just six different slash 24s that are being hosted in this particular |
| 2:06.1 | ASN. And it only has one upstream provider, and that's Stormwall, which is an anti-DDoS provider. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

