meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, September 16th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 16 September 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Misc Locky Updates; WebEx Update; Windows Malware Attacking iOS/Android

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, September 16th, 2016 edition of the Sands and its Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich and today I'm recording from Las Vegas, Nevada.

0:12.0

Let's start with a couple of updates regarding the old favorite Lockhears Ransomware.

0:17.0

Apparently it no longer now connects back to a command and control server in order

0:23.6

to retrieve an encryption key and register the infected system. That's now all done on the system itself.

0:31.6

Of course with that there's less infrastructure to maintain for the bad guys and also detection becomes slightly more

0:39.5

difficult. Now there are also some reports that Locky may be moving to a different

0:45.2

downloader but so far I'm really still just seeing the SIPT office documents with

0:52.3

some kind of visual basic or other script that then does the download.

0:57.9

Anti-malware detection is still pretty mixed here. In particular, anti-malver has a hard time

1:03.8

with the downloader. Often it misses the downloader, but then later does detect the actual malware being downloaded.

1:12.6

The problem with this is like yesterday I was playing with some malware,

1:16.6

it just keeps trying different versions of the malware until it finds one

1:21.6

that actually then slips past the detection and I've seen it try like about a dozen different versions here.

1:29.3

One of the problems here of course is that the user may actually believe then that

1:33.3

the anti-mal resolution is effective and the exploit got stopped but the user will

1:38.8

still end up with an encrypted system in this case because one of the ransomware samples does make it past the check.

1:49.0

And Cisco released a critical patch for its WebEx meeting server.

1:55.0

So this only affects the server component if you're just run declined.

2:00.0

You don't have to worry about it or if you're

2:02.4

using Cisco's own servers in order to hold your meetings.

2:07.6

The problems here is that the meetings server suffers from an unauthenticated remote code

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.