meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, December 18th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 18 December 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. ZIPed Maldoc; Memes Covert Channel; Shamoon is Back

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, December 18th, 2018 edition of the Sansanet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and I'm recording from Washington, D.C.

0:13.6

Now, I always encourage you to send us malware samples or whatever you sort of see being odd in your network.

0:21.7

One of our readers, Jason actually followed my advice and not only sent us the malicious

0:27.6

document, but also his rather complete analysis.

0:32.4

So Didier wrote it up?

0:34.3

And now one interesting little twist on this was this was one of these documents that

0:39.9

arrives as an encrypted zip file now of course the password is usually mentioned in the email

0:46.8

but the email by the time that jason got a hold of this particular zip file was no longer available

0:53.8

so he actually had to use a little tool.

0:58.0

He used F-GRAGSIP and this particular tool takes a password list.

1:02.0

And now of course these encrypted zip files that usually see as email attachments,

1:08.0

well, they tend to have simple passwords.

1:10.0

So wasn't really all that terribly

1:12.9

difficult to find it here using one of the standard password lists. So thanks again, Jason,

1:19.2

for sending us this file in your analysis, and for more details, as usual, refer to the diary.

1:27.6

Not just earlier today in class, we were talking about covert channels,

1:32.7

and so it fits quite nicely that Trent Micro has a blog post

1:37.5

about an interesting cover channels via malicious memes

1:41.7

that they discovered for a particular piece of malware.

1:46.5

This malware is watching a particular Twitter account

1:50.1

and waiting for images to be posted with a particular URL patterns.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.