meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 6th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 March 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Survey Phish; Not a Corona Phish; Loss of Trust; Revocation Stop @certifygiac

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 6th, 2020 edition of the Sands and at Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.3

Sort of interesting fishing email today that Xavier is going over.

0:16.5

This one does not use of the typical trick where they find a random website, compromise it,

0:22.1

and then insert the fishing page.

0:24.5

Instead, they're using an existing service here, surveygismo.com, to launch their fishing

0:30.6

attack.

0:31.6

Surveygismo, like other similar websites, allows you to set up online surveys and they

0:36.8

just sort of create their fishing page

0:39.5

as a survey essentially and with that they hope to bypass some filters. On the other hand,

0:46.4

the page doesn't really look all that plausible I find, so not sure how many users

0:52.8

actually fall for this.

0:55.5

And talking about fishing mentioned yesterday, a coronavirus.

1:00.0

I just received an email that was not a fish that came from healthcare.gov,

1:06.2

but sort of had all the hallmarks of a phishing email.

1:11.3

So if you have users submitting emails as fishes

1:16.1

that contain a link to lnks.gd,

1:20.9

that apparently is the domain that the US government is now using

1:24.4

sort of as a short link, click-through count. I'm not really sure why they need

1:28.9

a short link for a link in an email, but either way makes the email look very suspicious.

1:37.3

And comment any users submitting it to you as a possible fish, because it really should not be a

1:43.0

link that anybody clicks on.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.