meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, June 18th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 June 2018

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SMTP Exfil Puzzle; Encrypted Office Documents; Recent Port 8000 Scans; WebUSB Issues

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, June 18th, 2018 edition of the Santernet Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:12.4

Lorna got a real nice puzzle on Friday if you're interested in cryptography, that may be something

0:19.0

for you to look at, but apparently what we're

0:22.0

looking at here is some kind of command control channel or X-FEL mechanism.

0:28.1

The data is being sent to a domain do not spam today.com and contains as subject three sort of

0:36.3

random letter combinations, then the letters MID colon, and then what

0:41.6

looks like sort of an MD5 hash. The body is then again what looks like eight words, but really

0:48.6

just the random characters. So not really sure what is this all about, but if you did see similar emails

0:57.0

leave your network and in particular if you were able to capture any of the malware responsible

1:04.0

to it, then please let us know. Or if you're just interested in a little crypto puzzle,

1:09.0

well, maybe you can take a stab at it

1:11.4

and figure out what algorithm, what keys are being used in this case.

1:17.7

And DDA came across an interesting trick with office documents.

1:23.7

Turns out that if office documents are encrypted using the password Velvet Sweatshop,

1:30.3

they will be displayed automatically without the user having to enter the password.

1:36.3

The reason for this is that apparently old versions of Excel had this as a default password,

1:43.3

and for backward compatibility, well, a new version of

1:47.0

Excel will just automatically open documents encrypted using this particular password.

1:53.5

Of course, this may still throw off some anti-malware solutions that will not open the document

1:58.9

because it is encrypted and because they do not know

2:02.5

about this fairly uncommon default password.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.