ISC StormCast for Monday, February 15th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 February 2021
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, February 15th, 2021 edition of the Sandstone at Storm Center's Stormcast. |
| 0:08.2 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.9 | Looks like at least are from anecdotal evidence that lately we have seen a little bit researching of CHM files. |
| 0:22.4 | These are Microsoft Help files. |
| 0:24.9 | Used to be really popular in malicious attachments, but have been fading off until recently. |
| 0:32.7 | And the idea here is that these CHM files contain HTML that, since it's executed locally, |
| 0:42.0 | can then execute JavaScript that in turn, at least here in the example that Xavier came across, |
| 0:49.0 | is used to launch PowerShell. |
| 0:51.2 | Of course, once you have PowerShell, then the sky is the limit, and here |
| 0:55.8 | additional matter is being downloaded and executed. So it doesn't really give the attacker |
| 1:01.8 | any new capabilities. They didn't have sort of an existing, sipped JavaScript and HTML files, |
| 1:07.0 | but typically the reason why attackers are trying and rotating through different |
| 1:13.2 | extensions like this is just to see if you let down your guard, you're no longer looking |
| 1:18.8 | at these particular files, and as a result, they may be able to slip in some malicious content. |
| 1:27.8 | And SIFT, a company that helps prevent payment card fraud, has come across an interesting |
| 1:34.5 | scheme how fraudsters are able to monetize stolen account and credit card data. |
| 1:42.4 | Now, it's not always payment information that's being stolen here, |
| 1:45.9 | but in this particular case also login information for various food delivery services. |
| 1:52.6 | The way the data is monetized is that these fraudsters are then offering their services, |
| 1:59.6 | for example, via telegram, and the individual is then |
| 2:04.3 | able to place an order via Telegram using the fraudster at, of course, a substantial discount. |
| 2:12.4 | So it's a little bit like buying a super discount stereo of a van at the side of the road. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

