4.9 • 696 Ratings
🗓️ 25 April 2025
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, April 25th, 2025 edition of the Sands Internet Storm Center's |
0:07.6 | Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:14.0 | Well, in Diaries today, some of our honeypots got scanned for what looks like attempts to use them as SMS gateways. |
0:23.6 | The URLs suggest that the attacker here is looking for SMS gateways made by Teltonica. |
0:31.3 | Teltonica makes a wide range of SMS gateways from IoT-centered devices to Enterprise enterprise gateways but the fundamental idea of all of |
0:40.3 | these devices is that you're connecting to them via an IP connection and then use them to send |
0:46.6 | SMS messages this of course happens via a relatively straightforward API and and well, as so often, there are some default |
0:58.9 | users and default passwords that are being used. |
1:02.5 | That's exactly what the attacker was looking for here. |
1:05.7 | Typically, according to the documentation I found, there is a user one that's always defined. Now, its password is usually |
1:14.7 | a user underscore pass, but looks like an addition to that one password. They're also looking |
1:21.6 | for a couple others, not sure if they're just common passwords being used or depending on the exact |
1:26.7 | device. They're looking for whether or not |
1:29.5 | there's a range of different default passwords being used. There's one that's a little bit |
1:35.7 | interesting, if anybody has any idea, this P8XR password, that's sort of just a random string. |
1:42.6 | Google search didn't return anything for this random string. |
1:46.7 | Now, in order to confirm whether or not the particular gateway they're connecting to is able to send SMS messages, |
1:54.2 | they're then sending a quick test to one of the attacker's phone numbers. |
1:58.4 | And there are two phone numbers that we have seen so far, one in Saudi Arabia and |
2:04.2 | one in Belgium. |
2:05.7 | Of course, they themselves could then be again some kind of SMS to email gateway or something |
2:11.6 | like this that would then be used to receive those messages. |
... |
Transcript will be available on the free plan in 20 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.