ISC StormCast for Monday, December 19th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 December 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, December 19th, 2020 edition of the Sandcent Storm Center's Stormcast. |
| 0:08.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.3 | This weekend, we had a diary by Guy about a malicious email impersonating HSBC. |
| 0:19.6 | The email, oddly enough, used an authentic HSBC phone number, |
| 0:24.7 | but it was a phone number in Luxembourg. Now, Guy is in Canada, doubt that was used |
| 0:31.1 | of the target, the particular geography, maybe that they try to use a legitimate phone number, |
| 0:36.9 | but one that people are unlikely going to call. |
| 0:41.0 | But the goal here is not to trick users into logging into a fishing website. Instead, the user is |
| 0:47.9 | supposed to open the enclosed attachment, which then of course turns into malware as Guy find out an info stealer. |
| 0:55.9 | So that's probably how your credentials are going to get lost, not via fishing. |
| 1:01.3 | Guy is demonstrating a quick walkthrough in how to decode and quickly analyze the file with CyberShef. |
| 1:08.7 | It's one of those, well, arrives as a zip file. |
| 1:11.1 | When you unpack it, it then becomes one file with double extensions in order to confuse |
| 1:17.2 | the user and maybe some automated tools a little bit about what the type of the file is. |
| 1:24.1 | And then we got more end-to-end encryption news from cloud services. |
| 1:28.5 | Google now announced that it will keep email bodies and attachments encrypted in its server. |
| 1:35.0 | For now, the feature will be enabled in beta versions for Google Workspace customers. |
| 1:41.3 | So that's when you actually pay for Gmail. Not sure if this will eventually |
| 1:46.4 | trickle down to sort of the free accounts, but of course it may also hurt somewhat of the |
| 1:52.3 | target advertisement and such that Google typically uses to monetize the free Gmail accounts. |
| 2:00.1 | If your account is eligible, so you have basically the right |
| 2:04.4 | type of account, then the administrator can request access before January 20th. And again, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

