ISC StormCast for Tuesday, April 14th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 April 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, April 14th, 2020 edition of the Statenet Storms, Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and I'm recording again from Jacksonville, Florida. |
| 0:15.0 | Jan took an look at two different fishing emails that were sent three months apart and appear to come from |
| 0:23.2 | the same actor. |
| 0:25.0 | It's sort of interesting to see how these phishing emails and related attacks are evolving |
| 0:31.5 | over time or, well, how they're not evolving. |
| 0:34.5 | In this case, they haven't really been evolving too much. For three months, |
| 0:39.2 | this particular actor pretty much sent the identical email messages with some customizations |
| 0:45.9 | and used pretty much the same fishing site where the user then entered their credentials. |
| 0:52.4 | I guess if attackers wanted to do a lot of work, they would |
| 0:55.7 | get legitimate jobs. On the other hand, well, if it works, they're probably just going to stick |
| 1:01.6 | with it and just fine tune the message a little bit in order to make it work better. But this also |
| 1:08.2 | shows that they're not really considering much like spam filters and |
| 1:12.4 | the malware and such, which over this time frame probably should have captured this particular |
| 1:19.0 | attack. |
| 1:20.4 | Also, so an interesting little titbit that Jan noticed is the actual page where the user |
| 1:26.3 | enters the credentials. |
| 1:31.5 | I've seen this a few times before with phishing sites where they always reject the first username and password combination. |
| 1:36.5 | I believe they do this in order to evade users |
| 1:40.7 | who think that they may have clicked on a phishing email and they're now entering |
| 1:46.9 | a wrong username and password first, thinking that if it's a fishing site, well, it will tell |
| 1:52.9 | them the password is correct because the fishing side typically sort of accepts any password |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

