ISC StormCast for Friday, August 16th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 16 August 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, August 16th, 2019 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich. |
| 0:09.4 | And today I'm recording from Jacksonville, Florida. |
| 0:14.5 | Did he take a closer look at a malicious word document that was recently used in a more targeted spearfishing attack and |
| 0:23.6 | well actually proofpoint wrote about the attack itself. What Dede did was take his well-known |
| 0:32.6 | scripts to analyze this document and show how to overcome various obfuscation techniques used in this |
| 0:42.3 | particular case. |
| 0:43.3 | Sort of interesting here and not really unusual is that the actual malware was sort of encoded |
| 0:51.3 | as a PM file format. |
| 1:01.1 | So PM is often used in certificates, but the reason attackers like to use this particular format on Windows is that they can use cert util, which is typically used to read certificate |
| 1:07.9 | files that are PM decoded to decode the file and then create the executable. |
| 1:16.4 | This, of course, is also supposed to evade some of the simple signature-based detection because you |
| 1:21.9 | no longer see the typical PE header that you have in Windows executables. On the other hand, as the D.D.A. points out, |
| 1:30.9 | with PM certificates, the first letter actually should be M. But if you have another file just |
| 1:38.7 | encoded as a PM certificate, that's no longer the case. So that's actually something |
| 1:44.0 | that could be used as |
| 1:45.2 | a signature to find these odd or invalid PM certificates. And I think pretty much every week |
| 1:53.4 | we have a couple of IOT security issues or failure of end of things security. Actually, I remember last week I didn't cover a couple stories that were kind of interesting |
| 2:04.6 | just because I figured, well, we had too much IoT security already to talk about. |
| 2:10.6 | And well, you probably noticed it keeps repeating some of the issues that are showing up. |
| 2:15.6 | Well, if you just thought that the issues |
| 2:18.6 | keep repeating, there's now some confirmation here from Sarah Satko with the Cyber Independent |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

