ISC StormCast for Thursday, October 3rd 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 October 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, October 3rd, 2019 edition of the Sands and at Storms and as Stormcast. |
| 0:07.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Got a post from Brad today about the latest version of Emot Head. |
| 0:18.8 | What's sort of different about this version is in how it actually |
| 0:24.2 | creates the spam emails it's using to trick other users into infecting themselves. In this case, |
| 0:32.4 | it went into the infected machine's email history and did pull an email out and then crafted a reply |
| 0:42.0 | with an attachment. |
| 0:43.5 | Now the email picked and the message added aren't really connected, so that seems to be all |
| 0:51.1 | pretty much random, but still of, this significantly increases the chances of someone falling for actually |
| 1:00.0 | opening and running the attachment. |
| 1:03.0 | The attachment itself is your standard Word document with macros. |
| 1:08.0 | So you have to enable macros and it will kind of trick you into enabling |
| 1:13.1 | macros by claiming that office is not activated. |
| 1:17.6 | And this is how the user is tricked into enabling active content, which then of course will |
| 1:23.0 | allow macros to run. |
| 1:25.5 | Personally, I have run into sort of occasional activation notices from office, |
| 1:30.9 | in particular if I wasn't connected to the internet and the like. So users may actually be |
| 1:37.0 | somewhat used to seeing messages like this, which of course then increases the probability |
| 1:42.9 | that they will actually enable macros. |
| 1:47.0 | I'm talking about some of these generic user awareness items, |
| 1:52.3 | Sands Security Awareness, released its latest OCH newsletter. |
| 1:57.1 | This is typically directed at a less technical audience than the audience usually |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

