ISC StormCast for Monday, November 16th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 16 November 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, November 16th, 2020 edition of the Santernut Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich. |
| 0:09.1 | The time recording from Jackstable, Florida. |
| 0:12.8 | To start out with a couple of quick diaries from this weekend. |
| 0:18.0 | First off, all, DDI, yet again, updated Olli Dump, the tool that he maintains, |
| 0:25.0 | that allows you to analyze various office documents. And one thing that he has run into and |
| 0:32.3 | talked about quite a bit recently is malicious documents where actually anti-malver has removed macros. |
| 0:39.8 | So he introduced a new indicator to let you know that a macro has been removed from a particular |
| 0:47.0 | document. |
| 0:49.3 | And Xavier took a quick look at a sample at the found on virus total. |
| 0:53.3 | That's actually based on a fairly old piece of JavaScript malware back from 2018. |
| 1:01.6 | But thanks to some really all that complex but innovative new obfuscation technique has gotten a new lease on life by again being able to evade anti-matter. |
| 1:15.7 | What it does here is pretty easily just take Unicode codes and then with a simple math formula, |
| 1:24.8 | transform the character code to an ASCII code that then translates into |
| 1:31.4 | the malicious script. |
| 1:34.0 | And the release of macOS, Bixer, and a number of other new software packages such |
| 1:41.4 | buy Apple on Thursday caused an interesting issue for macOS users |
| 1:48.0 | trying to launch software. Many macOS users reported that it was quite slow to start software |
| 1:56.2 | on Thursday evening. I remember myself sort of running into this a little bit, but kind of striking |
| 2:02.5 | it off as well, maybe my system is doing a little bit too much. That moment didn't really have |
| 2:09.9 | the time to track it down. But apparently what happened was that Apple's OCSP service was overloaded. OCSP stands for the online certificate status |
| 2:21.3 | protocol and it's a service used to verify if a particular certificate is still valid. This is also |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

