ISC StormCast for Friday, October 20th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 October 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, October 20th, 2017 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and the I'm recording from Singapore. |
| 0:12.3 | Brad today discussed in two different diaries how currently the Locky Ransomware is being distributed. The first one is sort of interesting. I haven't actually |
| 0:22.4 | seen that yet and it involves an ISO file as an attachment. Now ISO files are typically used |
| 0:31.3 | for CD-ROMs, DVDs. That's their file system. But yes, you can use them as standalone files and if you're double |
| 0:41.5 | clicking on them in Windows then the ISO will be opened just like a CD-ROM and you have |
| 0:49.2 | access to the files inside now as Pratt does discuss in diary, this doesn't really appear to evade any |
| 0:57.2 | antivirus. So not really clear why this is done, maybe just to evade some of the simple email |
| 1:05.1 | filters that just do delete or block certain file types like the very common SIPD JavaScript files that we had |
| 1:15.5 | in the past, and ISO files may not be on those blacklists. So within that ISO, you do have |
| 1:23.8 | the actual executable and the malware relies on the user clicking and running it. |
| 1:31.0 | The second trick used by lock is something that we have talked about a couple times in the last |
| 1:36.9 | few weeks and that's the DDE attack. |
| 1:40.7 | This is where VIRT actually calls an external program in order to provide it with additional data. |
| 1:48.0 | Well, in this case, this external program is malware. |
| 1:53.0 | And as talked about before, the user will see plenty of warnings. |
| 1:58.0 | And again, essentially, the malware relies on the user just |
| 2:02.3 | executing the malware. And then we got an update on Coin Hive, the cryptocurrency |
| 2:08.6 | miner that has been spotted on numerous websites. Well it turns out that the |
| 2:14.5 | people behind Coin Hive have changed directions and they now have an |
| 2:20.9 | alternative that they call off-mine. Now off-mine does explicitly request permission before |
| 2:28.7 | actually starting its mining task and with that they're hoping that anti-malware will no longer block |
| 2:37.3 | their miner. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

