meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, January 14th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 14 January 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Hancitor is Back; Intel Anti Ransomware; Clouds Rain; SAP Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, January 14th, 2020 edition of the Santernat Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich.

0:09.7

And the name is I'm recording from Jacksonville, Florida.

0:14.2

Well, must be nice to be a bad guy that develops malware because you get to take an entire month off over the holidays and

0:23.6

New Year. At least that's what it looks like for the Hankytore Malware. This is

0:29.6

Malware that Brad Duncan has been tracking for quite a few years now and well last year

0:36.6

on the 17th of December the Malware went quiet. No new

0:41.8

samples had been discovered, but all for a sudden on Tuesday, it started up again. So I guess

0:49.5

their vacation was over. That's also kind of a sign of how professionalized some of these

0:57.1

Malware teams have become. And really, the Malware sort of picked up where it left off

1:02.6

back in December. So not really a lot of changes here or sort of development during the time

1:09.8

they went offline.

1:11.6

It starts with a docuSign email, a fake docusine email,

1:16.6

that asks you to click or to view an invoice,

1:19.6

which then will send you to a Google hosted document.

1:23.6

Google, common theme that we have seen also

1:25.6

and talked about last year is sort of becoming a

1:29.3

favorite hosting facility for a lot of these malicious document. And then the document, of course,

1:35.6

when you open it, it's avert document. We'll ask you to enable macros because apparently

1:41.1

the document is protected. At least that's what it pretends to be.

1:47.1

So really good old word macros are then being used to download additional malware.

1:52.6

One interesting thing that Brad notes with Hank Hattor is that as long as the user that's being infected here is connected to an active directory

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.