4.9 • 696 Ratings
🗓️ 12 May 2022
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, May 12, 2020 edition of the Sands and its Storm Center's Stormcast. |
0:08.5 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:14.5 | Brad has one of his famous Malware walkthroughs, and this time it's the TA 578 group that is pushing isophiles in order |
0:26.0 | to spread the bumblebee malware. |
0:29.4 | Now, what's sort of interesting about this is that they're using threat hijacked emails. |
0:34.2 | What that means is that they actually already compromised a system and then they're |
0:39.9 | checking the email conversations on the hijacked system and are injecting themselves into existing |
0:48.0 | email threats. So you may receive a reply to an email that you sent earlier that contains the malicious document, |
0:57.3 | which of course makes it much more likely that you're going to open the file, in particular |
1:03.5 | since in this case the file is an ISO file. |
1:07.0 | A second sample that Brad is walking through uses a SIP archive that's password protected, |
1:14.3 | sort of as an immediate step, before you are actually getting to the ISO file. Also interesting, |
1:20.5 | the actual download links are exclusively using storage.govopiys.com. That's, of course, a very common location |
1:30.8 | for malware these days, but popular enough for legitimate content that you probably have a hard |
1:38.9 | time monitoring downloads from storage.govio APIs.com. |
1:45.7 | And affirming Google's ranking towards the top of matter distributors, NetScope did a report |
1:53.8 | on phishing downloads and saw that not only there was a sharp increase, no big surprise |
2:00.2 | here, but also that one of the |
2:03.0 | techniques that they really saw increasing is search engine optimization techniques |
2:07.8 | in order to improve the ranking of malicious PDFs. And the number one download site here |
2:16.1 | was Google Trive. |
2:18.7 | So not the API, but still Google Properties. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.