ISC StormCast for Friday, December 16th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 16 December 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, December 16th, 2020 edition of the Sandsenet Stormsanders Stormcast. |
| 0:09.5 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.3 | Well, we got a Malar Analysis diary again by Brad and Brad. |
| 0:20.2 | This time looks at how a Google ad led to an |
| 0:24.2 | iced ID or a bog bot infection. This is sadly still a very common theme. You are searching for |
| 0:31.6 | some legitimate software and the top ad being displayed on Google is leading you to a malicious page. |
| 0:40.7 | What makes it, I think, inverse is that when you see a paid ad like this, the URL displayed |
| 0:47.0 | is something that the attacker may pick, so this is not the actual URL that you'll end up at. |
| 0:55.6 | Yes, I understand this may be a little bit required, |
| 0:59.3 | because often ads lead you to some kind of click-through URLs and such, |
| 1:03.8 | not to the actual company homepage, and advertisers want to have their brand visible here in the link, |
| 1:13.8 | but allowing advertisers to arbitrarily pick the link being displayed, of course, leads to fraud like this, and apparently |
| 1:20.0 | Google doesn't have much interest in blocking this because there's an issue that's going on |
| 1:24.8 | for a few years now. Not sure with Google now owning Mannion if you |
| 1:30.1 | get like a 10% off coupon if a Google ad did actually cause the compromise. After the user |
| 1:38.2 | does end up on the fake software page in the case that Pratt talks about its NEDESK, there is a zip file that's |
| 1:47.5 | unavailable for download, which will expand to an MSI, so an installer file. And once installed |
| 1:55.3 | this, well, that's when you'll install the malicious DLL for Iced ID. |
| 2:01.6 | All the packet captures and other artifacts can be downloaded and you can sort of reproduce |
| 2:07.6 | some of the analysis that Pratt performed here. |
| 2:11.6 | And Tallus has an interesting write-up on a recent Quackbot variant |
| 2:18.3 | that takes advantage of SVG images. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

