4.9 • 696 Ratings
🗓️ 3 June 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, June 3, 2025 edition of the Sands Internet Storm Center's Stormcast. |
0:07.7 | My name is Johannes Ulrich, and this episode brought you by the sands.edu graduate certificate program |
0:15.5 | in industrial control systems security is recorded in Jacksonville, Florida. |
0:22.2 | Well, in Diaries today, Xavier came across an interesting malware sample that takes |
0:26.4 | advantage of SSH on Windows. |
0:29.3 | That's something we have seen for years and years in Linux. |
0:32.6 | Linux, of course, always had SSH as one of its standard components, typically pre-installed. Now, Windows started |
0:40.9 | doing this a couple of years ago, and now, pretty much any new Windows system that you are |
0:48.2 | using has an S-H-Kline, at least pre-installed. Now, the S-clined, of course, does not listen on any port by default. |
0:57.1 | That's exactly sort of what that malware takes care of. |
1:01.1 | It does deploy a simple S-H-clined configuration file that will basically instruct the system, |
1:10.8 | the S-H client, |
1:11.8 | to connect to a particular command control server |
1:14.4 | and then forward connections from that command control server |
1:18.4 | to an internal listening port. |
1:21.8 | As Xavier points out, this configuration file is actually not 100% syntagely correct. |
1:27.8 | So it probably doesn't work quite the way it was deployed here. |
1:32.1 | The particular command control server, yes, it's no longer listening. |
1:38.2 | I would just want to point out that they're using S.H. |
1:41.0 | Over Port 443, of course, that's supposed to better blend in with a common network traffic. |
1:48.7 | However, if you do have any kind of network monitoring system, |
1:52.5 | that should really raise a flag if you all for a sudden have S-H over port 4-43. |
... |
Transcript will be available on the free plan in 14 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.