4.9 • 696 Ratings
🗓️ 17 July 2017
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, July 17th, 2017 edition of the Sands and Storms, and as Stormcast. |
0:08.0 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:12.4 | And I'll actually be back in Europe. |
0:15.0 | Last week, October, I'll be teaching intrusion detection in depth in Berlin. |
0:20.8 | For details and other classes I teach, just |
0:23.3 | check the show notes at the bottom of the page you'll find the list. But let's take a look at |
0:29.8 | Diaries on Friday. Brad wrote about Nemecut AS and the mal-smam that actually distributes it. |
0:38.0 | Nemecut AS is a ransomware. |
0:41.4 | Luckily, there is a decryptor available for it. |
0:44.1 | So if you are being hit by this, there is a chance for you to recover your files. |
0:49.2 | It typically arrives as usual with a downloader that's an sipped JavaScript file and claims to be a |
0:57.7 | UPS delivery notice. This particular wave is going on for a couple weeks now and Pratt as usual |
1:06.3 | does have indicators of compromise, traffic captures, and some history about this particular |
1:13.6 | ransomware family. |
1:15.6 | And now, one thing we always like is if users send us in any malicious documents or so |
1:21.6 | that they received. |
1:23.6 | DDA looked at a recent one. |
1:25.6 | It was an Excel spreadsheet and it contained a Windows shortcut, a link file. |
1:31.4 | Now, the DEA used OLLI Dump here in order to analyze this particular file. |
1:37.6 | The link file, and I think I mentioned this before, does then download additional malware to the system. |
1:46.6 | It accomplishes this via PowerShell and well, the URL here is sort of split up in order |
1:53.2 | to obfuscate it somewhat. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.