ISC StormCast for Thursday, September 19th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 September 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, September 19th, 2019 edition of the Sandsenet Stormsenders Stormcast. |
| 0:09.0 | My name is Johannes Ulrich, and I am recording from Stockholm, Germany. |
| 0:15.1 | After disappearing for a few months earlier this year, Emotad has really been back with vengeance and is, well, |
| 0:24.8 | back to its old tricks of serving as a distribution network for various malware. |
| 0:31.8 | So, Brad wrote up a diary about a sample that he ran across earlier this week and he's discussing some of the traffic |
| 0:40.2 | that he observed from this particular sample. |
| 0:43.8 | Interestingly, while the email actually was used to trick the user to load the malicious |
| 0:50.0 | document here was written in German and actually this particular emote head strain has caused |
| 0:56.9 | some ransomware infections and such in particular in Germany that sort of made the news. As usual |
| 1:04.5 | you have to enable macros now emote head is pretty good instead of coming up with the right |
| 1:09.7 | reason for a user to |
| 1:11.6 | actually do that. |
| 1:13.9 | And in the example that Brad looked at, then Trickbot was installed as payload for EmoTed. |
| 1:24.1 | And Microsoft appears to have some ongoing issues with its Windows Defender product. |
| 1:30.3 | Now, one bug that was sort of ongoing, I believe since August, was that when you ran it |
| 1:36.3 | in the command line with SFC slash scan now, you actually got an error that there was a corrupt |
| 1:43.3 | file. Now, last week Microsoft released a new version of Defender 4.18.1908.7 that appeared to have |
| 1:54.8 | fixed this particular issue. SFC slash scan now, now appeared to work fine. |
| 2:01.3 | But apparently, this new version also added a new bug in Windows Defender. |
| 2:06.0 | If you are running a full or a quick scan on your system, it will only scan about 40 files. |
| 2:14.4 | After that, it will stop without displaying an error. |
| 2:18.4 | Now of course that leaves most of your files unscanned and may lead to actual malware being |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

