ISC StormCast for Thursday, August 20th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 August 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, August 20th, 2020 edition of the Sandcent, |
| 0:06.3 | and it's Storm Center's Stormcast, my name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.2 | Little treat today from Xavier who walks you through a somewhat unusual obfuscation technique used by a recent sample of QuagBot. |
| 0:25.2 | It was delivered as one of those DocuSign documents and emails that you've probably seen quite |
| 0:32.3 | frequently. In this case, the macro that then actually caused the quagbot sample to be loaded had this |
| 0:41.9 | interesting obfuscation technique that Xavier took apart for you. |
| 0:47.0 | What's also sort of interesting is that the file name actually depends on the current timestamp |
| 0:53.0 | on the system, downloading the file. |
| 0:56.0 | Now, what Xavier here assumes is that the file name actually doesn't matter. |
| 1:00.6 | It's being used to download the sample. |
| 1:03.8 | Instead, that's probably more meant to sort of obfuscate the request as it's traveling on the wire. |
| 1:10.5 | So, for example, someone observing these |
| 1:12.7 | downloads may not necessarily see a lot of documents being downloaded using the same |
| 1:19.5 | file name. Xavier, in addition to decoding this scheme that's being used to create the file name, |
| 1:25.5 | also decoded 10 different host names that are being used to create the file name, also decoded 10 different host names |
| 1:29.3 | that are being used to download this sample. |
| 1:34.8 | And we got the interesting paper from a group of German security researchers that looked |
| 1:40.3 | at problems with encrypted email, and they looked at common with encrypted email. |
| 1:45.0 | And they looked at common open PGP and SMIM implementations. |
| 1:50.0 | They looked at 20 different male clients and found eight to be weak to actually in some cases |
| 1:58.0 | pretty easy to exploit vulnerabilities. |
| 2:01.9 | Four of these clients were actually vulnerable to something they call a mail-toe key |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

