ISC StormCast for Monday, April 20th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 April 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, April 20th, 2020 edition of the Sandton Storm Center's Stormcast. My name is Johannes Ulrich. And yet again, I'm recording today from Jacksonville, Florida. |
| 0:17.1 | Xavier on Friday looked at yet another COVID-19 related piece of malware. |
| 0:22.6 | Now, the malware arrived with sort of a COVID-19-related email, |
| 0:27.6 | but what's kind of special about the malware is that the malware itself was fairly generic |
| 0:33.5 | and sort of used a template to create the email that would be used to spread it, but also a related malicious RTF document. |
| 0:42.4 | This RTF document exploited the equation editor vulnerability. |
| 0:47.7 | That's a little bit older vulnerability, but we still see this being abused quite a bit in these malicious emails, and the actual exploit in the |
| 0:58.2 | template did launch calc.exe, the Windows calculator, which is a standard sort of proof-of-concept |
| 1:04.3 | kind of exploit, and it would then just swap it out for whatever PowerShell script, this particular |
| 1:10.5 | version of the attack was going to run. |
| 1:13.7 | Also sort of interesting, the Malware would actually only really run if you're running Outlook, |
| 1:18.2 | and then it would email itself to all of your Outlook contact. |
| 1:23.7 | So an example of commodity Malware that we see just being spread out to millions of victims |
| 1:29.3 | in the hope that a couple of them will fall for it. |
| 1:34.3 | And on Friday, I reported how a signature update to Microsoft security apparently caused some |
| 1:41.5 | problems and crashes for users. |
| 1:44.6 | Looks like Microsoft did the expected thing and published a new signature update that should have fixed this. |
| 1:52.0 | Now, no action should really be necessary at this point unless you're still experiencing the crashes. |
| 1:58.5 | In which case, you need to trigger a manual update of the signatures, |
| 2:02.5 | and that should hopefully take care of your problems. |
| 2:06.8 | And talking about security software going bad, |
| 2:10.2 | Sophos had to remove a firmware update for its UTM devices. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

