4.9 • 696 Ratings
🗓️ 9 August 2021
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, August 9, 2021 edition of the Sands and the Storm Center's Stormcast. |
0:08.2 | My name is Johannes Ulrich, and the time, recording from Stockholm, Germany. |
0:13.2 | On Friday, Xavier walked you through a yet another malicious VERT document. |
0:18.4 | What's sort of special about this is not just that a reader submitted the |
0:23.1 | document but well this reader actually also clicked and executed the document by mistake. |
0:30.7 | Common trick here, the sender was spoofed and resembled a known person to the victim. |
0:38.6 | So that's how it often happens. |
0:40.8 | Maybe the sender got also compromised themselves or sometimes even just accidentally the email does look right or just matches something that's currently going on. |
0:54.8 | So Xavier took the opportunity to walk you through various obfuscation techniques here and how to |
0:59.6 | recognize with roughly simple means that this is a malicious document and what it is trying to |
1:07.5 | accomplish. |
1:09.6 | Abuse.c.H. for a while now is operating a malware bazaar, and |
1:14.2 | what's of special and, I guess, different between malware bazaar and a virus totalist, that |
1:20.0 | malware bazaar makes it easy to download a malicious sample. So great to get training material if you are doing reverse |
1:29.6 | analysis. Well they now added a new service you can actually download a |
1:35.6 | daily zip file with all the samples that they received that particular day. |
1:41.9 | They're created around midnight but they're asking you not to download |
1:45.7 | them exactly at midnight because it takes a while for everything to sort of get sipped up and |
1:50.6 | probably don't want to flood them all with requests just at exactly the same time. |
1:57.3 | A couple of months ago, I talked about how a number of languages, Pearl and Python, for example, |
2:02.8 | had a very similar vulnerability in that they didn't validate IP address correctly, in particular |
2:10.1 | if the Octal format was used. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.