meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, September 21st 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 21 September 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Python in Word Docs; Salesforce Phish; Google Appspot Phish; Sysmon Clipboard monitor

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, September 21st, 2020 edition of the Sandtonet Storm Center's

0:06.8

Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:14.1

Oh, the weekend we had a couple of interesting diaries, one from Xavier, where he went hunting again on Byrus Total for office documents

0:24.2

with interesting objects. And now what he came across, there is something that also

0:30.5

did he publish about earlier, and that's documents that include Python code,

0:38.3

which is a little bit odd because of course typically on Windows systems

0:42.3

and you would expect a Windows system to open the office document,

0:47.3

you don't have Python typically installed.

0:50.3

So Python, if it's used on Windows systems, often arrives compiled. This code would

0:58.1

only run if Python was already installed on the system. Now, he found actually a couple

1:04.9

different samples there. Some looked like they may be experiments, maybe someone is of developing

1:10.8

some exploits here,

1:12.5

or internal red team exercises because they tried to connect to internal to 192-168 IP

1:19.5

addresses.

1:20.6

We also found a third address.

1:23.5

That's a 156.132 address.

1:26.4

And that one is now actually assigned to the United States courts system.

1:32.6

So kind of interesting there.

1:35.0

It wasn't always assigned to them if you're looking up in some IP address information system,

1:42.1

so it may not necessarily come back with anything yet.

1:47.0

Let me got a second diary by Guy.

1:49.9

Guy is writing about Fish trying to impersonate Salesforce.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.