4.9 • 696 Ratings
🗓️ 7 June 2022
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, June 7, 2020 edition of the Sandsenut Storm Center's Stormcast. |
0:08.0 | My name is Johannes Ulrich, and the time I'm recording from San Francisco, California. |
0:14.0 | There's still no update regarding a patch for the MS-MSDT vulnerability, aka Fallina. |
0:21.3 | Various organizations have spotted exploit documents as a follow-up to yesterday's |
0:27.7 | diary where Diddy explained how to analyze an MSMSDT exploit sample. |
0:34.3 | Didier today went into more detail on how to use his OLLI Dump tool and the |
0:41.3 | CLSID plugin to analyze these types of documents. Using these tools and a new, as he calls it, |
0:49.3 | work in progress module, DDA created to extract data from all these streams. |
0:55.0 | Using these tools, it is relatively straightforward to extract any URLs. |
1:01.0 | And of course, that's how you then get with these documents to the actual malicious part |
1:08.0 | that's downloaded as part of this template. |
1:12.5 | So with no patch available, more and more exploits being cited in the wild. |
1:17.7 | I hope you'll find these tools useful if you run into a suspect document to possibly |
1:23.7 | figure out what they're trying to accomplish. |
1:28.7 | And cloud security company CloudSec has a nice write-up on a newer fishing campaign |
1:35.7 | that heavily relies on URL shortners and EURS proxy services. |
1:40.2 | This is sort of a trend that has really been ramping up this last year. I have seen a |
1:47.2 | couple of examples too. And the tricky part here is that the attacker basically will use a |
1:52.4 | URL shortener to point you to some service like NCRC or one of these sort of developer-centric |
2:00.3 | proxy services and then point that |
2:03.6 | proxy to the actual fishing site. The disadvantage for the defender year, of course, is that, |
2:10.4 | first of all, now your indicators of compromise change all the times, usually sort of with a 24-hour rhythm, these URLs change. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.