meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, October 24th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 24 October 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Sczriptzzb and Netsupport; rtfdump; Windows MotW Bypass; Fake GitHub Exploits; F5 and Synology Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, October 24, 2022 edition of the Sandsenet Storm Center's Stormcast.

0:09.6

My name is Johannes Ulrich and I'm recording from Augusta, Georgia.

0:15.7

Brad in the diary from Friday looked at one of those tech support scams you may have seen. The scam

0:22.6

starts out by displaying a pop-up tricking the user into installing a fake browser update.

0:30.0

Brad calls this particular scam script is spisen, if I pronounce this correctly. It's the particular name that the JavaScript uses that is being injected into websites to display the pop-up message.

0:46.3

In the past, Brad observed these scripts installing solar marker matter, but more recently recently it switched to net support rat.

0:58.0

More details and indicators of compromise can be found in Brad's diary.

1:04.0

One interesting tidbit here, it also installs a Russian version of Google Chrome. Did he over the weekend wrote a diary with some hints to use his RTF dump tool?

1:19.6

RTF documents still frequently used as malicious documents and well a part of the reason

1:25.6

they're popular is that you can obfuscate parts of them and

1:30.7

makes it more difficult to analyze them of course and more difficult to identify them as malicious

1:38.2

did they added the dash capital f option to the tool and this helps you identify and de-officiate

1:47.4

some of the more popular obfuscation tricks. If you use this dash-capital F option, or find

1:55.4

option, the tool will look for hexadecinal strings ininesal strings in the document and it will then attempt

2:03.3

to decode them.

2:05.5

DDA shows how the option works and uses a malicious RTF file downloading the form book

2:11.9

malware to demonstrate how it all works.

2:17.5

And talking about bypasses, we got more ways to bypass the mark of the web in Windows.

2:24.6

This is, of course, something that Microsoft sort of has been improving over the years.

2:29.8

The mark of the web is this alternate data stream that's added if you download a file from the

2:35.6

web and it's supposed to trigger warning messages as a user attempts to open the files,

2:41.1

particular execute files.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.