meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 20th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 June 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Formbook; ZIP Bruteforcing; .inf Malware; FortiNAC PoCs;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, June 20th,

0:03.4

2003 edition of the Sands and Stormsendors Stormcast.

0:08.5

My name is Johannes Ulrich.

0:10.4

And today I'm recording from Jacksonville, Florida.

0:15.0

We've got a couple of interesting diaries over the long weekend.

0:18.9

First of all, Brad published another one of his walkthroughs.

0:23.1

This time, an other case of a forum book, actually. There's a little bit of focus of Brad this month.

0:31.5

It does arrive as an email with an Excel attachment. This attachment is actually exploiting a rather old vulnerability, 2017, and that is then

0:42.6

being used to load an executable.

0:45.7

This executable will, after a reboot, because that's how it makes itself persistent.

0:51.8

Also, download and base 64 encoded DLL

0:57.6

that then loads

0:59.5

Formbook. Formbook is

1:01.9

a pretty common

1:04.1

kind of piece of malware, has been

1:06.0

around for a while, and

1:07.7

Brad has been written about

1:09.7

this in the past. but it's one of those

1:12.6

mouse that sort of keeps changing, also the infection chain, how it ends up on system, keeps

1:19.6

changing.

1:20.6

Interesting that it uses this old war on ability here in this case, but that's also part of some

1:26.6

of this malware where it's going after systems

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.