ISC StormCast for Monday, February 21st, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 February 2022
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, February 21st, 2022 edition of the Sansonet Stormsendors Stormcast. |
| 0:08.4 | My name is Johannes Ulrich. |
| 0:10.0 | And I'm recording from Jacksonville, Florida. |
| 0:14.1 | Big thanks, as always, to our readers who send us interesting Malver Xavier looked at a recent example that claimed to be sort of a PDF. |
| 0:24.4 | The extension was dot tar. |
| 0:27.5 | Dot LC, but the file name ahead of the extension ended with a PDF. |
| 0:32.7 | I guess that's sort of how they try to make it look like a PDF. |
| 0:36.7 | Other odd thing, the dot-lc extension is usually not recoverable with Windows. |
| 0:44.1 | If you just click on it, it'll tell you need to load the appropriate tool from the app store. |
| 0:51.6 | Turn out to be just compressed and tart. |
| 0:56.5 | And then inside you didn't have a PDF, no, it was your usual visual basic script. |
| 1:03.0 | And Xavier is going through the decode of that script to figure out what it's eventually attempting to accomplish, |
| 1:10.5 | which in this case was installing a copy |
| 1:13.6 | of Remko's rat. A couple takeaways from this. First of all, of course, attackers are always trying |
| 1:19.5 | new things. They may not initially make sense, but well, still worth for the attacker to give it a try |
| 1:27.1 | and essentially see what sticks. |
| 1:30.2 | So be very of any unusual extensions hitting your users in email attachments. |
| 1:38.8 | And if you've got a critical vulnerability in the Cassandra no SQL database. Cassandra is an Apache project. Now, before you get |
| 1:49.0 | too varied, it's not exploitable in the default configuration. The problem here is that |
| 1:56.0 | Cassandra offers the option to provide user-defined functions. |
| 2:01.4 | And these functions are written in JavaScript, but can call Java, |
| 2:06.5 | and they are running in Cassandra's own sandbox. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

