meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, December 4th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 4 December 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Banking Malware Uses Old Tricks To Avoid Detection; JotForm Phishing; iOS 11.2

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, December 4th, 2017 edition of the Santernut Stormsetters Stormcast.

0:07.9

My name is Johannes Ulrich and the day I'm recording from Jacksonville, Florida.

0:12.6

Every so often the bad guys just get lucky because we stop looking for some of these old attacks.

0:20.5

Renato has a recent example where Malver

0:24.2

actually used the good old Batfile in order to launch a script on Windows and then install

0:30.7

banking Malver. This particular Batfile has a virus total rating of 0 out of 58 and well it does install banking malware on

0:42.8

the user's system. Renato did observe this particular piece of malware intercepting traffic

0:49.9

to a number of different Brazilian banks. Now, they do play another trick that may contribute to

0:58.4

the low recognition, and that's that they actually claim that the file is UTF-16 encoded.

1:05.6

With that, if you look at the file using a standard editor, all you see is what looks sort of like Chinese

1:12.4

characters. I don't know if this fools any of the Anavirus tools, but it potentially did

1:20.1

contribute to the low virus total score. And then we got a second interesting diary. This one

1:27.0

by Xavier, he wrote about how jawodform is being abused by fishing kits. Jod forms is a cloud service that allows you to set up simple forms and collect data your users, enter. Well, in this case, the data is provided by a fishing site.

1:47.5

Tricks like this make it quite difficult to spot these fishing attacks. One of my tricks

1:53.8

to look for malicious activity is always to look for odd domain name lookups and I always recommend looking for that certainly

2:02.3

quite valuable but in this particular case all you would have seen is a DNS lookup for

2:07.9

Jodform which is a legitimate and somewhat popular site so it's probably something that you

2:14.9

may even whitelist.

2:23.2

And of all days on Saturday, Apple released a somewhat rushed update for iOS.

2:26.3

This is iOS 11.2.

2:29.3

It's a feature release of iOS. Now, the main reason this was released on Saturday was that it also addresses a bug in iOS

2:36.4

that became evident on December 2nd.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.