ISC StormCast for Thursday, December 19th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 December 2019
⏱️ 4 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, December 19th, 2019 edition of the Sandsenet Stormenast. |
| 0:06.4 | My name is Johannes Ulrich. |
| 0:09.1 | And today I'm recording from Jacksonville, Florida. |
| 0:13.6 | We've got another diary by Brad, and he's looking at the latest emotette activity. |
| 0:20.0 | Emotet, very, very active, really also in the news quite a bit. |
| 0:25.4 | And the latest message that he's sort of taking apart here is actually very straightforward. |
| 0:29.8 | One of those typical invoice messages that then attaches a Word document. |
| 0:36.9 | And of course, a Macro in the word document will then trigger |
| 0:40.0 | additional downloads. |
| 0:42.3 | Now, in this case appears that the malware was mostly used then to again spread the infection |
| 0:50.4 | further by sending emails. |
| 0:53.3 | Emothead is often used to sort of install these spam trojans on the system. |
| 1:00.4 | It infects. |
| 1:01.7 | Now, one trick that EMod hat uses a lot to appear more plausible is that it sort of injects itself |
| 1:08.5 | into conversations that it finds on the infected system. |
| 1:13.9 | And the German office for information security is warning that they are aware of a number |
| 1:21.8 | of systems affected in federal agencies that do just that. |
| 1:28.0 | So now it appears the email is coming from some kind of government agency that you're |
| 1:34.2 | currently communicating with and it sort of looks like a reply to an email that you send. |
| 1:40.9 | Of course, that makes this very dangerous because now an unsuspecting victim may be more |
| 1:47.4 | likely willing to, for example, enable macros on a document they receive. |
| 1:53.2 | And if you're looking for something to do next week, why not patch, Jumla, if you're still |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

