4.9 • 696 Ratings
🗓️ 21 March 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, March 21st, 2003 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Augusta, Georgia. |
0:14.0 | Xavier came across yet another fishing kit that takes advantage of telegram in order to exfiltrate credentials. What's really kind of |
0:22.8 | neat about these fishing kits is that they're all JavaScript, so all self-contained and don't |
0:29.4 | really require any kind of hosting infrastructure. Maybe on some case you'll just see them in |
0:35.4 | a compromised WordPress site, which I think is where Xavier found this particular fishing kit. |
0:42.7 | The code that's actually used by this particular example is amazingly simple. |
0:47.0 | It's a simple HTML form, and whenever the user submits it, it will actually insert a message that the password was wrong, |
0:55.1 | hopefully trickering the victim in supplying maybe other variations of their password that they |
1:01.4 | may be using on different sites. And then it will send the message to Telegram. The disadvantage of |
1:08.7 | this type of fishing kit is that all the credentials need to connect to telegram have to be provided in the open as part of the JavaScript. |
1:17.9 | And that's kind of where this particular attacker messed up in, well, not initializing that token that's actually needed to connect. |
1:26.3 | So as it is, as Xavi found this fishing kit, it's actually not functional. |
1:34.6 | And security company CoFense is reporting that the Emote Head Boardnet is back and |
1:40.2 | it's jumping on the OneNote bandwagon. |
1:43.9 | OneNote, of course, is the method de Jure in order to bypass more recent macro protections |
1:49.9 | that Microsoft implemented in Windows. |
1:53.5 | Other than that, the emails are sort of standard fare. |
1:56.2 | It's a SIP file, in this case a SIPPed OneNote file, |
1:59.9 | that will then download the EMOTDL file. |
2:06.4 | Well, if you are using Windows 11 version 22H2, so the most recent version of Windows 11, and |
2:13.5 | you would like to use the Unified Update platform or UUP with your WOS server, |
2:20.1 | then you have to apply an update actually to get all the latest quality and security fixes. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.