ISC StormCast for Monday, February 22nd, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 February 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, February 22nd, 2021 edition of the Sands and the Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.7 | And I'm recording from Jacksonville, Florida. |
| 0:13.7 | This weekend was sort of a flashback weekend that featured two diaries about DDE dynamic data exchange, a technology that has led to exploits, |
| 0:26.4 | well, back in sort of the early days, as far as I'm concerned, when OS2 was still a competitor |
| 0:33.2 | for Windows. DDE allows for many of the features that we now have in macros with that |
| 0:40.9 | malware that takes advantage of DDE is of course able to, for example, download and open |
| 0:49.4 | files from the internet. To the user, DDE actually sort of looks a little bit like macros in the sense |
| 0:56.6 | that once you open the malicious document, you do have to enable macros in order to allow |
| 1:03.6 | these DTEs to run. I assume that one reason why hackers tend to occasionally play with these older |
| 1:11.6 | techniques again is that they hope and well sometimes they're right about that that |
| 1:18.2 | modern anti-malver may have forgotten a little bit about these old techniques so it may not |
| 1:25.5 | detect this as malicious because after after all, there is no macro |
| 1:29.3 | present. |
| 1:30.5 | Xavier wrote about this sample on Friday, on Sunday. |
| 1:34.9 | We do have sort of a follow-up to this from DDA, where he shows how his oily dump tool |
| 1:41.1 | can be used in order to analyze these documents. |
| 1:46.3 | And researchers at Red Canary, VMware, and Malwarebytes have investigated and documented |
| 1:54.0 | some interesting Apple Malware and is yet another example of Malware that apparently |
| 2:00.7 | has specifically been compiled |
| 2:03.4 | for the M1 processor. |
| 2:05.4 | As so often with Mac Malver, it just asked the user to install it. |
| 2:11.6 | The ruse here apparently appears to be the very common Adobe Flash installer, which we have seen sort of as one of the predominant |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

