meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, March 10th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 10 March 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Self Modifying Excel 4 Macro; AMD Take a Way (or not); Google Play Protect Fail

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, March 10th, 2020 edition of the Sandsonet Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich, and the I'm recording from Jacksonville, Florida.

0:12.7

It looks like Diddy really sort of opened a large can of worms here with these XL4 macros.

0:19.5

Now, a lot of research, of course course recently has gone into Visual Basic for application code

0:25.1

in office documents and looks like there was a little bit of blind spot here for these

0:30.9

older Excel 4 macros.

0:32.9

We keep getting interesting samples from our user.

0:36.9

Did he just look at another one that came from our user.

0:41.4

Did he just look at another one that came from a user?

0:48.2

And what was interesting here is that the initial Excel macro actually downloads additional code from a website, adds it to a spreadsheet, and then executes it.

0:55.3

Now, initially we weren't able to get all of that code that it downloads, but eventually

1:01.5

the was successful via a virus total search to find the additional code which would download

1:09.6

more HTML actually and then again insert it

1:13.9

into Excel to execute it.

1:18.0

So these are some of these interesting multi-stage kind of exploits where you first have a

1:22.6

downloader that's then downloading additional code.

1:26.1

Have seen this a lot of course with a matter,

1:29.6

but really interesting to see how the same concept is being implemented here in Excel 4.

1:36.7

And then again, as a reminder, these Excel 4 macros, yes, they will run in the greatest

1:43.1

latest version of Excel. And of course often missed by anti-malware.

1:49.0

And then for a change, we don't have a side channel attack in Intel CPUs, but today against AMD CPUs.

2:00.0

This is where comes from researchers at the Technical University Kratz as well as the University

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.