meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, November 20th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 November 2020

⏱️ 16 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. PowerShell Drops Formbook; Google Phish; JARM TLS Fingerprint; ICS and IDS @sans_edu

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, November 20th, 2020 edition of the Sandcent, Center at Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:13.3

Saville today walked you through a PowerShell script that drops the formbook Trojan.

0:20.0

Now, what's sort of interesting about this is that, yes, of course, it's obfuscated and its

0:24.6

virus total score was a solid zero.

0:28.6

So no antivirus engine did detect this particular PowerShell script.

0:34.6

A couple of interesting tidbits here.

0:36.6

First of all, the code also checks if it's running

0:39.6

in a virtual machine and will refuse to run the PowerShell script and actually create some

0:47.2

DLLs that are being loaded. And the DLL is obfuscated with a tool called Cephyrus Protector.

0:58.1

A tool we kind of would like to know more about.

1:00.7

So if you're familiar with this tool, please let us know.

1:07.0

And I've mentioned before a couple times how Google's services are often being used for fishing

1:13.3

and how it can be quite difficult to take down some of these fishing sites.

1:19.2

Security Company armor blocks now has a nice blog post highlighting some recent fishing attacks

1:26.3

that take advantage of different Google services.

1:30.3

Google forms, of course, has long been used to collect credentials, even though most of these form pages have a fairly obvious warning not to enter any credentials.

1:41.3

Firebase storage has often been used to just store

1:46.4

the basic HTML for static websites.

1:49.9

And then of course, Google Sites has successfully

1:53.7

been used in order to, for example, create login pages,

1:58.6

like an example from Armor Blocks and Office 365 login page.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.