meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 11th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 11 June 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. ZLoader Update; More Expiring CAs; BLM Themed Malware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 11th, 2020 edition of the Sandshernd Storms, Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.3

And then I'm recording from Jacksonville, Florida.

0:13.9

Now, Brad today is updating us on C-loader.

0:17.9

He has seen it come in this week as a password protected Excel file.

0:23.4

Of course, macros again are to blame.

0:27.5

Now, kind of interesting here that the URL is actually only working if you are connecting to

0:35.1

it from outside the US.

0:38.5

This is kind of a rare case where the US apparently is not in the target range here.

0:45.3

Now we have seen sea loader go after other countries like just about a week ago I think

0:52.0

Brad wrote about a version of sea-loader where the email actually

0:55.9

was written in Polish.

0:58.3

So they may be diversifying here a little bit and maybe also trying to stay out of the view

1:05.7

of many of the U.S.-based security companies.

1:10.7

So the basic infection chain here is an email in English

1:14.6

that does have the Excel spreadsheet as an attachment.

1:19.7

The email claims that this is a resume.

1:23.3

So a little bit odd that it used an Excel spreadsheet,

1:26.8

not a Word document, but either way,

1:29.2

the password is listed within the email's text.

1:34.4

And then when you open the Excel spreadsheet, you're being prompted for the password.

1:40.1

And then, of course, you're also prompted to enable macros. As typical for a C-loader, it downloads

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.