4.9 • 696 Ratings
🗓️ 29 July 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, July 29, 2025 edition of the Sands and then at Storm Centers. |
0:07.3 | Stormcast, my name is Johannes. |
0:09.1 | Already recording today from Jacksonville, Florida, and this episode is brought you by the Sands. |
0:15.3 | EDU-cratid certificate program in incident response. |
0:20.1 | Yesterday, I think I mentioned these parasitic attacks |
0:23.9 | against the back doors that were left behind by SharePoint exploits, wrote up some of this |
0:30.0 | a little bit today, and also here a quick graph is what I published there, showing how these particular attacks evolved. |
0:39.8 | They started pretty much on the 20th. |
0:42.4 | That's sort of when this entire SharePoint issue sort of hit the news big time, then rose |
0:48.2 | quickly since then somewhat steady, maybe a little drop here the last couple of days, but many of these attacks are also |
0:57.2 | coming from researchers that are just trying to figure out how many systems are affected from |
1:02.9 | these attacks. Now, the other thing I publish as part of this is the different URLs that are |
1:10.2 | being hit here. |
1:11.9 | Interestingly, there's one URL that was hit on the 13th, |
1:16.0 | and also one of the 16th one really was just an exploit. |
1:20.2 | So on the 13th, the URL Teams logon.jspx was it not sure, it haven't had a chance to look at this on a real |
1:30.5 | SharePoint server to see if that URL exists. I don't think it does exist. So this would be |
1:37.2 | possibly an early left behind the sort of backdoor that someone was looking for here before the attack sort of really |
1:45.2 | blew up. Then on the 16th, we see the tool pane. ASPX. Again, that's from our honeypots. |
1:51.3 | So that's when we saw the initial attacks in our honeypots. And then, of course, it continues |
1:56.4 | on the 19th with SP install zero. They're varying also a little bit than the number here, |
2:02.3 | like SP install 8 was one or SP install X that we see, |
... |
Transcript will be available on the free plan in 7 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.