ISC StormCast for Thursday, March 8th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 March 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, March 8th, 2018 edition of the Sands and Stormsendors Stormcast. |
| 0:07.5 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:12.1 | The amount of ransomware we have seen lately has certainly declined and Pratt also states in his |
| 0:19.1 | last post that this is a trend that he's observing as well, |
| 0:23.4 | but nevertheless they're still out there. And earlier this week, he came across two updated |
| 0:30.3 | samples that he's discussing in his latest post. The two samples that Pratt found follow the very sort of standard pattern of |
| 0:41.0 | arriving as a word attachment in email, then they trick the user into enabling macros, |
| 0:47.4 | which then results in a PowerShell script, downloading additional malicious files. In order to trick the user into enabling |
| 0:57.3 | macros, these Word documents will display a message that tells the user that the document |
| 1:03.9 | was created in an earlier version of Word. And then you tell them, well, you can still look at a document, |
| 1:09.7 | but you first have to enable editing and enable content, which then is exactly what enables macros. |
| 1:18.4 | As usual, Pratt provides all the indicators of compromise and packet captures and the like that allow you to sort of test your own defenses, but hopefully you are already |
| 1:30.3 | defended against this kind of infection, because if it's not CryptoRansomware, they're |
| 1:36.8 | probably trying to find something else to install on your systems using these simple |
| 1:42.5 | verb macros. |
| 1:44.5 | And talking about CryptoRansomware, Malwarebytes has a nice blog post showing how to break |
| 1:51.8 | some encryption algorithms. |
| 1:53.9 | Of course, if the encryption algorithm is done well, there may not be really a way to break |
| 2:00.2 | the algorithm, but quite often in past versions |
| 2:04.1 | of crypto ransomware, the author made some sort of basic mistakes in how the encryption |
| 2:10.1 | was implemented, how keys were selected, or which exact algorithm was selected. |
| 2:16.3 | So this blog post gives you a little bit an insight in how to possibly defeat these weak |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

