meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, July 14th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 14 July 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VBA Details; Apple mount_apfs TCC Bypass

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, July 14th, 2020 edition of the Sand Center Storm Center's

0:06.2

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.0

Today we've got a couple of neat insights into Visual Basic for Application Code and

0:18.6

obfuscation techniques to make it more difficult to, for example,

0:23.5

detect macros or even just the presence of macros.

0:28.1

Diddy took a look at one particular Excel spreadsheet that Brad discussed a couple of days

0:35.0

ago.

0:35.7

And remember how I said that it's sort of surprising how these

0:39.3

type of Excel spreadsheets still make it to the user. Well, a couple of these techniques

0:44.6

could potentially explain why some users are still receiving them. First of all, it looks like

0:52.0

this particular document was perched.

0:56.1

Now, perching means removing the performance cache from the Visual Basic for Applications

1:02.1

Code.

1:02.9

Typically, you have sort of two parts.

1:04.6

You have the performance cache, which essentially is sort of a compiled version of the

1:09.0

code, and then you have to compress source code.

1:12.6

And of course, as the name implies, the performance cache is supposed to make the macro run faster,

1:20.0

which of course isn't necessarily a big problem for an attacker, so they just remove that part of the VBA code.

1:29.9

DDA believes that this particular spreadsheet was created with a library called EP Plus,

1:35.6

which is a C-sharp library that can be used to create Excel spreadsheets.

1:42.3

Secondly, turned out that the code was actually password protected.

1:46.2

However, password protecting Visual Basic for Application spreadsheet doesn't really do much.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.