meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Bad building blocks: a new and unusual phishing campaign. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Tech News, Daily News, News, Technology

4.81.1K Ratings

🗓️ 5 June 2021

⏱️ 19 minutes

🧾️ Download transcript

Summary

Guest Karl Sigler of Trustwave's SpiderLabs joins Dave Bittner to talk about their research: "Hidden Phishing at Free JavaScript Site". The research describes an interesting phishing campaign SpiderLabs encountered recently. In this campaign, the email subject pertains to a price revision, followed by some numbers. There is no email body, but there is an attachment about an ”investment.” The attachment’s convoluted filename contains characters the file-naming convention doesn’t allow, notably the vertical stroke, “|.” Even though "xlsx" is in the filename, double-clicking the attachment will prompt the user to open it with the default web browser. Thus, the file indeed appears to be an HTML document. Of course, it’s malicious. The research can be found here: HTML Lego: Hidden Phishing at Free JavaScript Site Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

Today's episode is sponsored by SRM, your first call for cybersecurity and

0:18.1

investigations. Threats today are evolving faster than ever before and since 2005 SRM has pioneered

0:25.3

tailored security solutions for global corporations and their executives.

0:29.5

Whether it's defending against cyber attacks with their award-winning team of ethical hackers and incident response specialists,

0:36.4

or navigating the murky waters of compliance and ESG challenges,

0:40.9

SRMs, Insight and Straight straightforward advice will help you navigate complex risks

0:46.4

and emerge more resilient.

0:48.4

Their secret, a culture that nurtures the sharpest minds, giving them access to the newest technologies and the freedom

0:55.3

to solve problems in new ways, enabling them to craft simple effective solutions for your

1:01.4

unique cyber challenges.

1:03.7

Search your first call to discover how SRM can help your business. Hello everyone and welcome to the CyberWire's Research Saturday.

1:26.7

I'm Dave Bitner and this is our weekly conversation with researchers and analysts tracking

1:31.6

down threats and vulnerabilities, solving some of the hard problems

1:35.2

of protecting ourselves in a rapidly evolving cyberspace.

1:38.9

Thanks for joining us. So one of the security research teams here at Trust Base

1:49.5

Spider Labs focuses only on email security and one of our researchers in the course of

1:55.9

doing their regular research on fishing attacks discovered this one

1:59.8

little fishing campaign that kind of stuck out as a little bit unique from what we usually see.

2:04.9

That's Carl Sigler. He's the manager of the Spider Labs Threat Intelligence Group at Trustwave.

2:10.5

The research we're discussing today is titled

2:12.5

HTML LEGO Hidden Fishing at Free JavaScript Site. You can sense the glory.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.