meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 24th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 February 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Excel Macros; VBScript Obfuscation; Letsencrypt; Google Play Malware; Google Warns of Edge

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, February 24, 2020 edition of the Santernut Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:13.0

One of the threats that doesn't appear to go away are Microsoft Office macros.

0:19.0

They're used to install a variety of malware, lots of ransomware, of course.

0:24.3

Typically, these macros are written in Visual Basic for applications or short VBA. VBA, well,

0:31.4

there was something before that, and that was the Excel macros. Now, often people still call some of these VBA script macros, but

0:40.3

Excel macros actually in older language that sort of predated VBA. And as often IT old features

0:48.3

never really go away and modern versions of Excel are still able to execute these older macros.

0:57.0

So did he look at one of these macros and wrote a diary about how to analyze them?

1:03.0

They can also actually show up in the modern open office XML files,

1:09.0

not just in the older XLS files that use the OLE format. Files can also

1:15.7

contain older Excel macros as well as the more modern visual basic for applications

1:21.6

macros, which then of course gives attackers the possibility to evade various signatures.

1:31.0

And talking about evading signatures, we also have a diary by Dillier.

1:35.8

He's going over a simple but pretty efficient visual basic script obfuscation technique.

1:42.5

The script was only 50 lines long and essentially what it did, it is downloaded a Puddy

1:48.4

client from an AWS website.

1:51.6

And the DA is showing how this Visual Basic script was obfuscated, essentially by replacing

1:57.6

the sort of signature strings with some random strings that are then being replaced

2:03.7

as the script is executed.

2:06.5

Nothing fancy, really, but this particular malicious script is only detected by one among all

2:14.9

the virus total engines that are currently in place.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.