ISC StormCast for Thursday, August 27th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 August 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, August 27th, 2020 edition of the Sansaernet Storm Center's |
| 0:07.3 | Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.5 | Today we had an interesting Excel spreadsheet that Xavier came across. It looked very malicious. |
| 0:21.6 | Well, it had some macros in it, but had a virus total score of zero, which of course |
| 0:27.6 | made it even more suspicious with all of these macros inside. |
| 0:32.6 | Kevin Beaumont on Twitter probably had some of the solution here to why this particular Excel spreadsheet had |
| 0:40.0 | such a low virus total score. Apparently, it already ran through some kind of anti-malware |
| 0:47.7 | security software, which modified these macros so they would actually no longer run. |
| 0:57.0 | So in the end, yep, it was probably originally malicious |
| 1:01.0 | and yes, the virus total score of zero |
| 1:05.0 | was not necessarily a bad thing in the sense |
| 1:07.0 | that it no longer executed any of the malicious code. |
| 1:12.6 | Now another Twitter user Will did run it through the Thor scanner, |
| 1:18.6 | and it actually associated this particular spreadsheet with the OilRick APT, |
| 1:24.6 | and this particular Excel spreadsheet was associated with Windows Update.me, |
| 1:31.1 | which also is associated with a similar Excel spreadsheet that will found that was named |
| 1:37.8 | Mofa VPN.xLS, where MOFA, that may stand for Ministry of Foreign Affairs. So, well, really interesting |
| 1:49.0 | what can happen with a more or less random weird Excel spreadsheet. And of course, |
| 1:55.3 | thanks to everybody who chimed in on Twitter. And Bit Defender has an interesting write-up how an APT group used a plugin for Autodesk's 3DS Max. |
| 2:09.0 | This is software that is used to create 3D models and visualizes them. |
| 2:15.6 | So in this particular case, it was used against an architecture firm, |
| 2:20.1 | which of course uses software like this in their day-to-day business. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

