4.9 • 696 Ratings
🗓️ 4 January 2024
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, January 4, 2024 edition of the Sansonet Storm Center's |
0:07.8 | Stormcast. My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida. |
0:14.5 | Jan today published a little bit a year in review post, summarizing some of the malicious |
0:20.4 | emails that he collected in his spam trap. |
0:24.7 | Now, one thing he points out is that the range of sizes of the malicious files is quite large |
0:32.3 | from about a kilobyte all the way up to a couple hundred megabytes. |
0:37.9 | We talk about some of these sort of excessive, large, malicious files that apparently |
0:42.8 | are attempting to bypass. |
0:45.0 | Some controls where anti-malibur only looks at files up to a particular size. |
0:52.6 | Other interesting findings here is, first of all, a lot of just simple PE files. |
0:57.7 | So standard executables, yes, with different extensions and such, but something that should |
1:03.5 | be pretty easy to detect, but also then a bunch of scripts, office files, PDFs, and |
1:09.8 | the like. |
1:10.5 | So what you typically see in malicious spam. |
1:14.1 | I think one important thing to remember is not to overthink what attackers may be attempting |
1:20.1 | with a particular sort of evasion method or what they're trying to accomplish. |
1:24.9 | Remember, attacks don't always have to work. They don't have |
1:29.0 | sort of a 5-9 SLA or something like this. An attacker often will just basically take a shotgun |
1:36.7 | approach where they try different tricks and hope that, well, one of their emails will make it. |
1:42.8 | But I think one lesson here to also remember |
1:46.0 | is that it's not that difficult |
1:47.2 | to really get rid of a large percentage |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.