ISC StormCast for Monday, December 5th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 December 2022
⏱️ 9 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, December 5th, 2022 edition of the Sanchez and its Storm Center's Stormcast. |
| 0:09.0 | My name is Johannes Ulrich and today I'm recording from San Francisco, California. |
| 0:15.1 | In Diaries this weekend, Friday, we had Brad talk about the latest update to the Q-bot or quackbot Malver. |
| 0:24.6 | What makes them so dangerous is the fact that once they infect a victim, the Malver injects |
| 0:30.4 | emails into existing email threats, malicious emails will then be sent as replies to emails. |
| 0:43.0 | The victim received, making it more likely, of course, that the receiver will think, |
| 0:49.5 | hey, this email, this attachment is actually valid and something that I need to check out. |
| 1:01.0 | What makes the latest version of this different than prior ones is that the attacker is now using VHD files. |
| 1:07.1 | VHD files are similar to iso files, basically disk images. |
| 1:13.6 | One disadvantage to the attacker of VHD files is that they require administrative privileges to mount and open. Other than that, the attack is similar to what we have seen |
| 1:18.8 | sort of with these ISO files in the past. Now, the administrative requirement, that only applies |
| 1:27.0 | if you're actually an active directory environment. |
| 1:30.4 | And never like you bought often targets sort of home users, small businesses that of course |
| 1:36.6 | are less likely to be part of an active directory. |
| 1:41.0 | Or if they do so, well, the user now needs administrative privileges. |
| 1:46.9 | And of course, again, in many of these sort of less maintained environments, you do have |
| 1:51.8 | everybody sort of running with administrative privileges still. |
| 1:57.9 | More details and the respective files are again available as links from the diary on Friday again. |
| 2:08.1 | And then over the weekend, Guy and Dede wrote two related diaries with binaries that are installed |
| 2:16.1 | in Windows but are typically more associated with Unix |
| 2:18.6 | and of course with things like ZH and such now being becoming part of Windows |
| 2:26.2 | you'll find them now more easily and of course malware or attackers can take |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

