meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 7th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 January 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. TAR Malware; ReiKey Protects Macs from Keystroke Loggers; Substition Cipher Font Phishing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, January 7th, 2019 edition of the Sands and at Storm Center's

0:08.0

Stormcast. My name is Johannes Ulrich and the day I'm recording from Jacksonville, Florida.

0:14.0

The DE came across some Windows malware that was distributed as a tar file. TAR files are very common for Unix

0:25.6

users, it's well the tape archive file format, but less common in Windows. And Windows itself

0:33.4

actually can't usually open TAR files. You need additional software but Winsip which most use install on Windows is able to open TAR files.

0:45.3

And as D.D.E points out, there are a couple of reasons why an attacker may select to send a TAR file.

0:53.3

First of all, well, like I just mentioned, it's not that uncommon that users actually have

0:59.8

software like WNSIP to open TAR files.

1:03.1

And secondly, TAR files may not be inspected by anti-malware and even if they are inspected,

1:10.2

that standard signatures may not necessarily

1:12.6

find the malware.

1:14.6

Didier also pointed out another trick that specifically applies to TAR files.

1:20.6

And that's in Windows.

1:22.6

If you download a file normally over the internet, Some metadata is added as an alternative data stream

1:29.2

that labels the file as downloaded from the internet and if you try to execute it, it will pop up

1:37.0

a warning if it's an executable. Well, the tar file is labeled as such, but you can open the tar

1:43.0

file without seeing a warning because you're not

1:45.3

executing anything. And then if you extract the executable inside this tar file, this metadata,

1:52.8

this alternate data stream is not transferred to the file. So now you can execute the file without any warning. And that may be why they're

2:04.9

doing this, why they're using tar files. Yes, they may lose some victims that are not able to

2:09.7

open the files, but on the other hand, they may gain more by actually not displaying this warning.

2:26.3

Patrick Waddle came out with yet another free security tool for Mac OS. Now this tool, Raykey, I think that's how you pronounce it, is able to detect some keystroke loggers.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.