ISC StormCast for Thursday, January 30th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 January 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, January 30th, 2020 edition of the Santernet Storm Center's |
| 0:07.0 | Stormcast. My name is Johannes Ulrich, and the time I'm recording from Augusta, Georgia. |
| 0:13.0 | Early this week, I talked about how big news events are often picked up by malware to trick users into clicking and opening malware |
| 0:23.3 | attachments. Well we have sort of two interesting examples that show this effect, but |
| 0:30.4 | actually in very different ways. The first one is from the US recent trickpot sample |
| 0:37.4 | and what it apparently does is that it attaches is from the US recent trickbot sample. |
| 0:45.4 | And what it apparently does is that it attaches excerpts from news articles about the Trump impeachment to the actual file. |
| 0:48.2 | Now, this text is not meant to be read by the user. |
| 0:51.8 | It's part of a binary file or XIF tags that are being added |
| 0:56.5 | to the file, but apparently it's meant to trick anti-mail-ware into letting this malware |
| 1:05.5 | in. Now it's not really clear if this technique works here. There has been some work recently where some artificial |
| 1:13.6 | intelligence engines could be fooled into allowing Malvern pass by just attaching benign code |
| 1:22.1 | to the binary. I don't think that same principle would sort of apply to text, but you never know. |
| 1:29.3 | And maybe the Malvern writers here know something that I don't know. |
| 1:34.3 | I've certainly seen similar techniques, for example, used to full anti-spam filters and such, |
| 1:39.3 | but that's when you usually expect text. So not as sure if this additional text in binary files would really make |
| 1:48.0 | a difference. |
| 1:50.3 | Now, unlike in the US, where impeachment, of course, at the top of the news still in Asia, it's |
| 1:55.6 | the coronavirus, and Japan has seen some EMOTET emails that do use the coronavirus to trick users into opening attachments. |
| 2:06.6 | What they're doing here is the email sort of looks like an official announcement. |
| 2:11.6 | It's coming from some disability health care provider, |
| 2:15.6 | at least that's what it claims to come from. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

