4.9 • 696 Ratings
🗓️ 25 June 2018
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, June 25th, 2018 edition of the Sansonet Storm Center's Stormcast. |
0:07.0 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:12.0 | A reader sent us on Friday an interesting email that included an XPS attachment. |
0:18.0 | Now, these are attachments you don't really see often. XPS here stands for |
0:24.2 | XML paper specification and as Lorna describes it sort of sounds like Microsoft's answer |
0:30.8 | to PDF essentially an XML file that can be used to distribute marked up text. In this case it turned out to be just spam. |
0:42.3 | Lorna says the idea here is probably to bypass various filters that block sort of known malicious or known unusual attachments, |
0:52.3 | but XPS for not being used very often probably hasn't made it |
0:58.4 | to any of these blacklists. |
1:01.6 | And Palo Alto's Unit 42 came out with a report looking at recent trends in exploit kits. |
1:09.0 | Now exploit kits are these building blocks that criminals use a lot |
1:14.4 | in order to spread malware. There have been less of them over the last year. And another |
1:21.6 | thing that Palo Alto reported was that there are really only eight different exploits being used currently |
1:29.3 | in the most prevalent exploit kits. |
1:31.3 | And while these exploit kits themselves are constantly being developed, and for example, |
1:36.3 | there are now new payloads like crypto coin miners, overall the exploits being used are not really all that cutting edge. |
1:44.8 | Now on the other hand, Malverabytes a couple of weeks ago came out with their own report. |
1:49.2 | Now their report covers a little bit more recent data and they saw one in an explorer and |
1:55.7 | one flash exploit being used that was from a couple months ago. |
2:01.6 | So they slightly paint a little bit a different picture, but I think one of the basic lessons here is that keeping your browser, |
2:09.6 | keeping your plugins up to date is really important and probably the best thing you can do against these exploit kits. |
2:18.3 | Yes, anti-malware helps too, but probably not as well given the wide variety in these exploit kits as compared to just keeping your system up to date. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.