meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, November 15th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 15 November 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. LokiBot Update; Zeek Packet-Fu; TPM Leaks; Zombieload 2.0

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, November 15th, 2019 edition of the Sanct Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.5

And today I'm recording from Riyadh, Saudi Arabia.

0:13.7

Well, with me skipping Thursday, I have two diaries to talk about.

0:17.6

The first one is one of Brad's famous Malver walkthroughs. This one is the latest

0:24.4

incarnation of Locky Bot, something that he has found this week. And in this example, well,

0:33.4

the bot arrives as an email, actually better set an email attachment, sort of

0:39.7

claims to be a document because it starts with docs underscore in its file name.

0:45.2

It's actually a RAR archive, so a compressed file.

0:49.0

If you uncompress it, it uncompresses directly in executable, but it does use the PDF icon to make

0:58.2

it more likely that the user will actually click and open it.

1:02.3

Over time, Lockybot Ridkey sort of has become a jack of all traits. It's still predominantly

1:08.1

sort of being advertised as an information stealer and key logger, but it can also

1:14.7

install additional files on the system.

1:18.3

Like I think it was a month or two ago I talked about it, hiding some of the information

1:23.4

in image files.

1:25.2

Then, for example, extracting additional executables out of these image files

1:30.3

in order to bypass some anti-malware tools. As usual, Pratt provides PCabs and samples

1:37.3

and links to reports from sandboxes, so you can easily replicate his analysis. The second diary we have is from Manuel.

1:49.0

Manuel looked at Seek.

1:52.0

Now, Seek I think, is still a little bit an underappreciated tool.

1:56.0

In particular, when it comes to network forensics, and Manuel shows some new little tricks how to for example

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.