ISC StormCast for Monday, February 14th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 February 2022
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, February 14, 2020 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.5 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.4 | Xavier has been hunting for isophiles that are being embedded in HTML and found another way how these isophiles are being |
| 0:25.2 | obfuscated. The latest example is apparently not at all recognized by any entire virus based on |
| 0:32.8 | virus total and it does encode the data as HTML ID attributes. |
| 0:40.6 | The document contains a number of paragraph tags. |
| 0:45.2 | Each one of them has an ID attribute and then JavaScript will just iterate through these |
| 0:50.8 | paragraph tags, extracting the ID attributes and then decode them to an invoice. |
| 0:57.7 | ISO file that's then presented to the user for download. |
| 1:03.7 | And to make things even more interesting, the ISO file does not include an executable, |
| 1:09.3 | but instead yet another visual basic script that then is executed |
| 1:14.9 | to load additional malware. |
| 1:18.3 | And the DLL that's being downloaded is hosted on the Discord CDN, which is yet another |
| 1:24.3 | sort of trick that's commonly used in order to make detection more difficult. |
| 1:30.2 | Well, to fight some of the exploits that may now be launched by malware like this, |
| 1:37.0 | we do have for a while now Microsoft's attack surface reduction tool that's part of its its Windows defender. And a good part here is |
| 1:48.2 | ASR, the attack surface reduction tool is getting better and better. One of the changes that Microsoft |
| 1:56.2 | published on Friday is actually preventing access to the LSAS process. |
| 2:04.1 | LSAS is responsible for authentication, so a common tool like mimic hats is often used to extract |
| 2:12.4 | credentials from LSAS, and with this new ASR rule, this is no longer possible. And now the block |
| 2:21.9 | credential stealing from Windows Local Secure the Authority subsystem, as this rule is called, |
| 2:27.8 | changed from not configured to configured and default mode is set to block preventing access. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

