meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 24th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 August 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Malware Loading Avast Safe Zone Browser?

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, August 24th, 2017 edition of the Santernet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Virginia Beach, Virginia.

0:12.8

Xavier came across a pretty interesting, malicious-looking email. Now, this email has a Portuguese subject that states that it does request a product

0:24.7

budget. Now, it does load a script that then, and that's where it gets interesting, really,

0:30.9

installs a binary that is validly signed with an AVASD certificate. Now, it identifies itself as the EVAST Safe Zone browser.

0:42.3

It does add some firewall rules, again, sort of odd and interesting,

0:47.8

and then adds itself to the run registry in order to gain persistence.

0:53.9

Not really clear what the end game is here,

0:56.0

whether it's actually the valid safe zone browser,

1:00.0

but that would be odd.

1:01.0

Behavior doesn't really match there,

1:04.0

or whether this is some kind of malware

1:07.0

that actually managed to adopt that particular certificate.

1:12.6

Now, the malware was downloaded via CDN, which did have a valid Zell certificate,

1:19.6

but it just used the host name for this particular CDN, so that's no real big surprise there.

1:26.6

One reader actually commented that the safe stone

1:29.6

browser maybe legit that it is the actual safe stone browser but it's really just

1:34.0

used to execute malicious DLLs that are actually being delivered with this

1:40.4

particular executable but by actually presenting signed and valid binary, people are more likely

1:47.9

going to execute it.

1:50.1

And Mindcast made big news yesterday with a new attack that they describe as a rope maker.

1:57.9

Now, what they're really talking about is is the use of externally

2:02.9

hosted style sheets in email. So if you're receiving an HTML email, there is of

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.