4.9 • 696 Ratings
🗓️ 4 April 2019
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, April 4th, 2019 edition of the Sansanet Stormsendors Stormcast. |
0:07.6 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:13.0 | Today we got a diary by Jim, one of our handlers who is into reverse analysis of malware. |
0:21.6 | He's actually also teaching a science class about this, and his diary is about how |
0:27.8 | hydra the tool that the NSA recently released compares to IDA, which is probably the most |
0:35.5 | common tool that people use these days in order to reverse |
0:40.8 | malware. |
0:42.2 | He will actually make a little bit serious out of these posts. |
0:46.1 | In this first one, he's talking about how to get Hydra to provide you with some of the |
0:51.3 | details regarding Windows API calls, which is a feature that Jim likes a lot |
0:56.4 | in IDA. And yes, you can have Hydra do similar things. And of course, it's less than two weeks |
1:07.5 | to the final tax filing deadline in the US. And this year, according to some |
1:14.3 | reports, the tax filing season is going to be a little bit more confusing and painful for a lot |
1:20.7 | of people due to all the changes in the tax code last year. So no surprise, the bad guys are trying to capitalize on this. As usual, |
1:31.4 | there is a good uptick in IRS and tax-related phishing emails. ProofPoint has a nice collection |
1:38.6 | of various fishing emails that they have seen. They also round out the list of examples with some non-US based fishing attempts. |
1:49.8 | So some for Canadian tax authorities, French, I think I've seen some, and British. |
1:56.7 | This is of course an international problem with fishing and you'll probably find some good |
2:00.7 | material in this proof point post to include in your own awareness presentations. |
2:07.9 | Now talking about security awareness, the Sands Securing the Human Project came out with its |
2:14.7 | monthly Oach newsletter. |
2:17.3 | This is again the newsletter that you can share with your less technical friends and colleagues. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.