meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 4th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 4 February 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. AZORult Triple Crypt; Sudo pwfeedback; Teamviewer Password Storage

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, February 4th, 2020 edition of the Sansonet Storms on a stormcast.

0:07.6

My name is Johannes Ulrich.

0:09.1

And today I'm recording from Jacksonville, Florida.

0:14.0

Jan came across an interesting malicious document currently being distributed via email.

0:20.1

The initial email actually actually not really all that

0:23.3

significant, just looked like the usual request for quotation style email. The document that was

0:31.0

attached claimed to be a Word document, but was actually an RTF, a rich text format document. Now, with RTF, you essentially now have the

0:40.9

ability to create some of these compound documents with various files. In this particular case,

0:48.0

the attacker choose to embed for Excel spreadsheets and automatically open them as the document is opened.

0:57.0

Reason behind having four Excel spreadsheets is that each one will ask the user to enable

1:03.0

macros. So by being sort of bombarded with these dialogues, they're essentially just hoping

1:09.0

that the user will give up and eventually click one

1:12.7

of the dialog boxes and allow the macros to run.

1:17.2

What's also sort of interesting with the particular Excel macro that of course then is being

1:23.0

loaded is that it is encrypted three times. Now of of course, the keys are included in the message.

1:30.8

So the encryption here is not really done to keep the content secret, but more or less just

1:36.3

to make it more difficult to reverse the particular document and also make it more difficult

1:42.4

for anti-melver to automatically

1:45.2

essentially unpack the malware using the passwords provided. Antomelver may be able

1:51.7

to do this sort of with one layer, maybe two, but of course the third layer was then added

1:56.8

to make it even more difficult for Antimmalware to automatically analyze this particular document.

2:04.6

The end goal here apparently is to install Azo Rult on your system.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.