meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 6th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 6 May 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Excel to Remcos RAT; FIDO Support; Heroku Breach

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, May 6, 2020 edition of the Sandsenet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and I'm recording today from Jacksonville, Florida, but actually teaching virtually in San Diego, California.

0:18.4

Brad was on duty again today, and Brad did write up an infection that led to Remco's rat.

0:27.1

Now, it started all out with the usual Excel file. It was in this case password protected,

0:32.6

with the password being a five-digit number listed in the malicious emails. Then, of course,

0:39.4

it tricked the user into enabling macros before downloading Remco's rad. One tool that I've

0:47.8

pointed out before, but really one mention again that came in handy here for Pratt was JA3 hashes.

0:56.6

JA3, a tool developed by security engineers at the Salesforce.

1:01.7

Essentially, hashes the client Hello packet that a client sends to a TLS server.

1:07.9

It looks at all the different options being used and how they're being used.

1:11.6

And in this particular case, the hash was specific to Remco's rat.

1:17.6

And emerging threats included that particular hash in its signatures.

1:23.6

So that's sort of how Brad was pointed into the right direction to then identify what's going on.

1:31.0

And also he then found the particular key log file. As usual, all the packet captures and such can be downloaded from links in Brad's diary.

1:41.5

And if you actually are interested in hearing more from Brad, Brad will be speaking

1:45.9

about some of these packed analysis techniques at our Sands Fire Conference as part of our

1:52.9

evening talks. And while having a password-protected Excel spreadsheet causing mayhem does sort

1:59.8

of fit its password day after all.

2:03.9

And well, as Brian Grebs actually noted in Twitter, it should really be enabled two-factor

2:10.1

authentication day not come up with stronger passwords.

2:15.3

Now, along those lines, Microsoft, Apple, and Google today announced

2:20.9

that they will support upcoming FIDO Alliance standards. And what's really so great about it

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.