meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firefox CT Policy; Veeam and Netgear patches

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 6 February 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firewall CT Policy; Veeam and Netgear patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, February 6th, 2025 edition of the Sands-Itonet Storm Center's

0:07.9

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.9

Well, today I wrote up some of these toll-smishing attacks. You probably got a few of them yourself over the last year or so the

0:23.5

setup is always the same. You're receiving a smishing message telling you that you're overdue

0:30.3

and paying the tolls, the highway tolls for your car, and it offers you a link to who then

0:36.1

pay the tolls.

0:39.6

Now, the attackers here are pretty good in sort of customizing these messages somewhat.

0:42.9

For example, myself living in Florida,

0:45.5

I am usually receiving messages on my Florida phone number

0:50.7

that refer to Sunpass, the Florida toll system.

0:55.7

The domains being used here often use Sunpass as part of the host name.

1:01.3

So a typical host name would be Sunpass.com, then a dash followed by some random characters.

1:08.9

And that's something that you may be able to use to detect users in your network

1:14.8

that may have fallen for one of these scams.

1:18.1

Take a look if there were any DNS lookups or HTTP requests for anything where the domain

1:23.9

name starts with Com Dash.

1:26.5

We do see about 100 to 500 of these domains being registered daily.

1:33.3

I don't think block lists are that effective because these domains are very ephemeral.

1:38.5

They use them only for a very short time.

1:41.3

But in hindsight, it may help your users if you identify anybody who may have

1:46.5

clicked on one of those links. Very importantly with these links, they usually tell you to reply

1:50.9

to the message with a why. This is in order to make it more difficult for phone companies

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.