ISC StormCast for Thursday, February 17th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 February 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, February 17th, 2020 edition of the Sansonet Storm Center's |
| 0:07.8 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.1 | Docustein is still popular in either fake or real messages. |
| 0:20.4 | Kind of interesting. Today we have a diary from Pratt |
| 0:24.1 | about a fake docu-signed message. And actually just a couple of hours ago, I received a real one |
| 0:30.0 | and asked the sender, well, whether or not it was real because the fake ones are so common |
| 0:36.6 | and often impersonating the real ones so well. |
| 0:40.3 | In this case, the case that Brad described, the link then led to the Asterooth or |
| 0:46.4 | Gilmah malware and, well, would lead to an infection if you let it play out. |
| 0:54.2 | Actually, this one for a change does not involve an office document with macros. |
| 0:58.6 | Instead, it's just a simple zip file that then expands to a CMD file, which of course |
| 1:06.0 | executes and downloads additional code. |
| 1:10.7 | And of course, as usual, you will find the actual Malar and P-Caps and such for your analysis |
| 1:18.7 | on Brad's website. |
| 1:22.1 | And we've got a couple of WarnerBILs here to talk about that you probably want to deal with before the weekend, if possible. |
| 1:31.2 | First, legislation did release updates for Confluence Server as well as for a GERA server. |
| 1:38.9 | The Confluence Server vulnerability is rated as high. |
| 1:42.5 | It's a privilege escalation vulnerability that would allow a local authenticated user |
| 1:48.8 | via DLL hijacking to then actually escalate privileges. |
| 1:54.8 | GERA suffers from a number of cross-site request forgery issues where an attacker could use them to then adjust settings. |
| 2:04.0 | Also, some data leakage issues. |
| 2:09.5 | All of these are only rated as medium, and I think that's appropriate. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

