meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, July 25th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 25 July 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SMS and Phishing; Sonicwall SQLi; SHA Errors;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 25th, 2020 edition of the Sands and its Storms,

0:06.4

and its Stormcast, my name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.5

Weaching talk, our handler from Singapore, came across an interesting fishing SMS message,

0:20.4

impersonating the inland revenue Revenue Authority of Singapore,

0:24.5

Singapore's Tax Authority.

0:26.8

In this example, the attacker did add some additional tricks to make the message more plausible.

0:33.8

First of all, the attacker spoofed the caller ID of the SMS message.

0:38.3

The caller ID used to then match a well-known Singapore bank.

0:44.0

By spoofing the caller ID, the message now shows up well in the same conversation as other messages that you received from the bank,

0:51.9

which of course makes it much more likely that a victim

0:55.5

will actually think the message is legit. Now what gave the message away here is that it sort

1:02.5

of followed a very common theme being used for a while now, and so users have learned to be

1:08.5

very of these type of messages. It basically states that the account was suspended because of a suspect transaction.

1:16.8

And then in order to restore access to the account, well, and help with the investigation also,

1:23.2

the victim should click on a link.

1:26.6

The link, of course, then leads to a phishing site, but only if the victim should click on a link. The link, of course, then leads to a fishing site,

1:28.8

but only if the victim uses a mobile browser.

1:32.6

If you're using a desktop computer,

1:34.5

well, then you will be blocked.

1:36.4

Also, if you are connecting from any of a known malware site,

1:42.2

IP address like VirusTotal and such, that will be blocked as well.

1:46.6

Block lists like this are not uncommon for fishing sites, and over the last few years, we have

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.