meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, September 26th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 26 September 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Teams Token Stealer; Downloading Malware; WhatsApp Patch; Sophos RCE Flaw; CircleCI Phishing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, September 26, 2020 edition of the Sands and its Storm Center's

0:07.5

Stormcast. My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida.

0:14.3

I've got a couple of interesting diaries this weekend that I would like to start out with.

0:19.0

The first one by Xavier is looking for examples

0:23.1

of malware exploiting the fact that Microsoft Teams is storing its authentication tokens in clear

0:30.7

text. I mentioned this vulnerability. I believe on Friday it was actually. So a last podcast last

0:37.2

week.

0:38.3

And Xavi ran a Virus Total query to find malware that attempts to access the respective files.

0:45.5

And after rejecting some false positives, he actually found a sample that matched the query

0:52.0

and indeed attempted to exfiltrate those tokens.

0:57.5

Interestingly, the sample was uploaded late last week and had a creation date, which of course

1:04.1

may be fake, exactly one month earlier. At this point, the file is recognized as malicious

1:10.1

by most anti-malalver products and identified

1:13.4

as a member of the Floxif Malware family. This Malver family, according to Malware Pites, is known

1:21.5

for modifying files and then attaching its own backdoor to these files.

1:31.4

So this may be a bit a new thing for Floxif,

1:39.0

but Xavier noted how this sample looks for cookies and other tokens in numerous other locations.

1:45.1

So it is not something that was specifically created to take advantage of the Microsoft Teams issue,

1:50.6

but they just added yet another spot to look for tokens.

1:58.5

I never ran to a Malware sample, but the sample, the Malver downloaded, appears to no longer available because while well, the domain was taken down.

2:02.2

D.D. has a quick recipe to try and find it. As long as you still know the IP address

2:08.5

associated with the domain, well, it's a simple curl request to connect to the IP address,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.