4.9 • 696 Ratings
🗓️ 15 June 2020
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, June 15th, 2020 edition of the Sandcent Storm Center's Stormcast. |
0:07.9 | My name is Johannes Ulrich. |
0:09.5 | And today I'm recording from Jacksonville, Florida. |
0:13.4 | Xavier came across an interesting Excel spreadsheet that used a couple new tricks in order to bypass anti-malver in particular being run in |
0:24.2 | a sandbox and also signatures. Now, as far as the sandbox goes, this macro will not automatically |
0:33.3 | run as the document is opened and some sandboxes rely on that happening. Instead, it actually |
0:40.8 | has a button that the user needs to click called document review that will then kick off |
0:47.3 | the macro. Now, the actual decryption of the malware only then happens as the user scrolls the document. |
0:55.8 | And another little trick that's probably really meant to make it easier to create new |
1:01.8 | documents as anti-malware vendors will come up with signatures is that it doesn't really |
1:07.5 | store the malicious code in a certain range of cells. Instead, it just |
1:13.1 | uses the XL cell type constants feature in order to enumerate all the cells with constants |
1:21.0 | in them. And well, that's where then the content of the actual malicious code is stored. So the attacker really can rearrange those |
1:29.7 | cons, not any time, use different content of those individual cells, and actually that content |
1:37.5 | is pretty small, so really doesn't make a lot of sense to sort of have a signature on one individual |
1:43.6 | cell. In the end, we get our normal |
1:47.0 | downloader that will then download the next stage of the malware. Sadly, at the time when |
1:53.8 | Xavier got a hold of the Excel spreadsheet, that domain did no longer resolve. It looks like we have at least one problem with last week's Microsoft updates and that |
2:07.1 | appears to affect USB printers. |
2:10.1 | Now lots of difference on a forum posts and such about it, so a little bit hard to tell |
2:15.1 | what exactly is happening here. |
2:26.4 | But apparently one problem is if you reboot the system while the printer is unblocked or turned off, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.