meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, June 26th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 26 June 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Modiloader Spam; Word Templates; Quakbot Obama271; MSFT Teams Phishing; Free Smart Watches;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, June 26, 2020, 3 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Stockholm, Germany.

0:13.7

Well, let's start with diaries. We actually had a number of good ones this weekend. First, a quick one by Guy.

0:20.4

Guy found two different modiloder attachments with, well,

0:26.3

a very different email ruses, actually. One was an email failure message, one of those Office

0:33.8

365 failure messages that are often being used to then trick users into opening attachments.

0:40.5

The second one, the message actually came from a magazine in Slovakia, sort of a lifestyle travel

0:48.5

magazine. That email was all in Arabic, interestingly enough. So very different lures here. The attachment in both

0:57.7

cases was a zip file that then turned out to be a modi loader, which of course is one of those

1:04.5

generic loaders that can load pretty much whatever malware you like. And Brad has written up a couple of incidents like this before.

1:13.6

More details, including screenshots of the emails, can be found in the diary.

1:19.7

And talk about malicious emails, Xavier found an interesting trick that has been used before,

1:24.7

but hasn't we been seen lately to attach malicious content to an office document?

1:32.3

No, it's not a macro this time.

1:34.9

It's a template.

1:36.3

And the interesting thing with templates is that they don't actually have to be included with a document,

1:42.8

but a document may reach out to a URL and then pull them in,

1:47.9

which of course makes it more difficult to detect these documents as they're going through

1:54.3

your email chain. The document will then be downloaded directly by Word as you're opening the document,

2:02.2

sort of at the time the user actually opens it.

2:05.9

In this case, the template was no longer available, so sadly, Xavi couldn't quite figure out

2:12.9

what this template then would have done to the user.

2:16.9

Also interesting that the template itself was

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.