ISC StormCast for Tuesday, December 10th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 December 2019
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, December 10th, 2019 edition of the Sandton, |
| 0:06.0 | the Storm Sunners Stormcast. My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida. |
| 0:12.0 | Well, when I received a suspicious word document earlier today, I knew Olly Dump is the tool I want to use and lucky for me. |
| 0:23.3 | We do have a current diary that Didier published yesterday that walks yet again through a current |
| 0:33.0 | malicious word document and shows how to extract and decode some of the malicious code embedded in |
| 0:41.6 | this document. Given the huge number of malicious documents that we keep seeing and also the |
| 0:48.6 | wide range of different sort of obfuscation techniques that the bad guys are using, these |
| 0:53.4 | diaries are always a great thing because you usually can't kind of use whatever is being |
| 0:57.8 | explained in this diary within a couple days. |
| 1:03.4 | And talking about new tricks, Sophos has a neat write-up with some details about the Snatch |
| 1:09.8 | Ransomware.atch Ransomware. |
| 1:10.8 | This Ransomware has been around for a while, but recently apparently added a new trick |
| 1:17.3 | to its repertoire where it reboots the system into Safe Mode. |
| 1:23.0 | So it will first add itself as a service to be started in safe mode, then it reboots the system into |
| 1:28.7 | safe mode, which will in this process disable most anti-malware products. |
| 1:36.1 | Malware has always tried to disable anti-malware software and typically just killed these processes, |
| 1:42.6 | of course, over the years, Antimalver has become |
| 1:45.9 | more resistant to these sort of simple shutdown attempts. |
| 1:50.4 | And I guess the simple thing about safe mode is that it's sort of one size fits all, pretty much |
| 1:55.6 | all anti-malware should be shut down in safe mode. |
| 1:59.6 | So the author doesn't really have to bother with |
| 2:03.6 | individual software and how to shut it down. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

