meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 16th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 16 April 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Hunting without IOCs; Cloudflare/Online Banking Outages; Crypto Stealing Chrome Ext.

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, April 16th, 2020 edition of the Santernut Storms,

0:06.0

and I'm a song, I'm a recording, from Jacksonville, Florida. Office documents with malicious

0:14.9

macros, well, one of the probably most common ways how organizations are being compromised these days.

0:22.6

So always interesting to look for new ways to figure out who in the organization has them

0:28.4

sitting on their system.

0:31.5

Rob came up with a real neat PowerShell script that you can use to hunt for these office documents in your network.

0:40.4

Now, in a couple things it does.

0:41.9

It first of all looks for office files that have macros in them, but then it can also check

0:46.8

if this particular document was downloaded from the internet.

0:51.6

It's sometimes referred to as the mark of the web, but documents,

0:56.8

files in Windows and actually other operating systems too like macOS have a marker that will

1:03.3

tell you whether this came from the local machine, the local intranet, a trusted site, or the

1:09.0

internet. So this is a great way then to figure out whether or not a file with a macro was downloaded

1:16.6

from the internet.

1:18.6

A third parameter that Rob can look for is Cerabyte Office files, but anyway, he wrote a pretty

1:26.6

nice and well documented PowerShell script that will look through all your files that you can use to actually spider your network for files that match these criteria.

1:38.0

He said he had quite a bit of success with this, not just to find actual malware, but also, well, users that just keep downloading

1:47.9

macro documents from the internet, whether they're being malicious or not, probably still a good

1:54.4

way to sort of look at these user systems to see if anything odd is happening.

2:01.1

And then we had today two unrelated events that caused outages, apparently, for a number

2:06.8

of different websites, or at least slow responses.

2:11.8

Well, let me head today two unrelated events that caused some outages for a number of websites. First of all, the last few days,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.