4.9 • 696 Ratings
🗓️ 24 August 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, August 24, 2023 edition of the Sandsenet Storms, Stormcast. |
0:08.6 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:14.5 | Excel continues to remain one of the favorite targets of attackers and attackers as well, find new ways to evade some simple filters |
0:23.4 | and deliver macro-Latin documents to end users. The latest example here is something Savier came |
0:31.4 | across. It's an X-LAM file. This is a macro-enabled add-in for Excel. The icon looks sort of somewhat like the |
0:42.2 | normal Excel macro. There are legitimate add-ins that are often being used like the solver add-in, |
0:48.3 | for example, or the analysis toolpack. They are usually pre-installed or quick sort of install in Excel, but this new |
0:59.2 | add-in now, well, it does execute code in the form of old style macros. |
1:04.7 | In this particular example, it then actually uses the good old equation editor trick that's |
1:09.7 | vulnerably back from 2017 to download additional |
1:14.8 | matter in the form of a visual basic script. So overall, nothing really terribly sophisticated |
1:20.7 | here, probably just going after users that have nothing to defend them, but some simple |
1:27.1 | rules that block certain extensions. |
1:30.2 | If you are one of those users, well, you now got one more extension to add to the list, |
1:35.4 | XLAM. |
1:37.4 | And while we're talking about Excel, Microsoft also announced that it will start supporting |
1:42.7 | Python in Excel. |
1:45.5 | So finally we get a real nice scripting language for all of these attacks. |
1:51.8 | And then we have more bad news for users of WinRR, the popular Windows compression software. |
1:59.1 | Group IB is reporting that they have seen active exploitation of a seraday vulnerability |
2:04.7 | in Winrara. |
2:06.0 | Exploitation goes back till April 2023. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.