4.9 • 696 Ratings
🗓️ 27 October 2016
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, October 28th, 2016 edition of the Sandtonet Storm Center's |
0:07.0 | Stormcast. My name is Johannes Orich, and I'm recording from Jacksonville, Florida. |
0:12.0 | The Locky Ransomware is making continuous changes to the emails that deliver its downloader today I actually saw two |
0:23.9 | different changes first of all they changed the content type to application |
0:28.8 | octet stream not the usual application sip and then actually a few hours |
0:36.0 | later they went with application X compressed. |
0:40.3 | All of this will have the same effect on the user that they'll be offered a compressed file to download. |
0:47.6 | And then when they run it, of course, the ransomware will be downloaded next. |
0:53.7 | But I think the goal here is to bypass some of the mail filters |
0:58.6 | that will look for specific content types |
1:01.8 | and then not filter some of these less common content types. |
1:07.4 | So make sure that you cover them all in. |
1:09.3 | If you see some of these downloaders make it |
1:12.9 | past your mail filter, then it's probably because of these new content types. Overall, |
1:19.5 | the basic scheme here still remains the same, where what you will be offered is a compressed |
1:25.4 | visual basic script or JavaScript or something along these lines |
1:29.7 | that will then download additional parts. |
1:33.5 | Now on the plus side here for the defenders, it looks like antivirus is getting a little bit better |
1:38.9 | in detecting these compressed downloaders. |
1:43.2 | Softos, for example, today got every single one of them as soon as I received them. |
1:49.9 | Symantec and Megafi still seem to have a little bit issues with the downloaders, |
1:54.6 | but I didn't do a complete run to see what happens when I actually ran these downloaders. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.