ISC StormCast for Thursday, April 18th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 April 2024
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, April 18, 2024 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.2 | My name is Johannes Ulrich, and today I'm recording from Washington, D.C. |
| 0:14.0 | In diaries today, we got a neat, malicious PDF that Xavier took apart, and he explains a little bit about how these type of |
| 0:24.1 | PDFs work. You probably have seen it. It looks like a blurred document with a clickable |
| 0:30.6 | button and then once you click on the button it will download the malicious file in this case |
| 0:36.3 | a zip file that turns out to be agent Tesla. |
| 0:40.4 | Xavier explains how to identify the URL that you're actually being clicking on, |
| 0:46.7 | and also how this annotation feature works, |
| 0:49.7 | that attackers are taking advantage here of in order to create these particular PDFs. |
| 0:57.0 | The reason behind these PDFs is twofold. First of all, the PDF itself is not really malicious. |
| 1:03.0 | It just includes a link to this malicious file. |
| 1:08.0 | Secondly, by using a PDF, instead of doing this, for example, as an HTML email, |
| 1:13.9 | the particular attack looks more plausible for a user to click on, and also is somewhat more |
| 1:19.8 | difficult to identify for various defensive software. And then just a quick update here on the Palo Alto issue. Palo Alto now states that |
| 1:31.6 | disabling telemetry is no longer considered sufficient in order to block the attacks. |
| 1:38.4 | Palo Alto did come up with new threat prevention rules, but in order to apply them, you do need to subscribe to the threat |
| 1:47.6 | prevention for your particular system. The patch works. It's really just the mitigation of turning |
| 1:55.5 | off telemetry that is no longer considered sufficient. And it sort of makes sense if you think about |
| 2:00.6 | it that the directory traversal in the code that is no longer considered sufficient. And it sort of makes sense if you think about it, |
| 2:05.1 | that the directory traversal in the cookie, |
| 2:06.2 | in the session ID, |
| 2:11.5 | really allows an attacker to write arbitrary files to the file system. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

