meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 26th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 26 May 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. PowerPoint Add-Ins and VM Malware; iOS Patch Analysis; eBay Scanner; iPhone Jailbreak

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 26, 2020 edition of the Sands and its Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.9

Unless you are sleeping under a real, real big rock, you are probably aware with how macros in Office and Excel can get started automatically

0:24.7

as a user opens the document.

0:28.2

Now, PowerPoint didn't really, at least at first look, have a feature like this, but Xavier

0:34.8

came across an interesting PowerPoint template that actually does just that.

0:41.8

Now, this PowerPoint template actually turns out to be a PowerPoint add-in, an extension to a PowerPoint,

0:48.5

and once the user opens it, yes, it's able to automatically execute macros using its own set of functions to do so.

1:00.0

In this particular case, it's actually even a little bit more twisted in that the macro is started when the PowerPoint file is closed.

1:09.0

They're using the auto close method here, probably trying to further

1:14.1

evade signatures that are looking for these specific features or functions that usually

1:20.5

are being called as the document is opened. And since the PowerPoint file is otherwise empty, it's likely that the user, after opening

1:30.8

it, will immediately close the document. You may learn more about this particular technique from

1:37.7

Xavier's diary who walks through the analysis of this particular file step by step.

1:45.0

And talking about odd ways to deliver Malware,

1:49.0

the Ragnar Locker Ransomware crew came up with,

1:54.0

well, a little bit of cumbersome way to deliver Malware

1:57.0

in delivering an entire virtual machine. Now, the virtual machine is the micro XP edition of Windows XP running within Oracle Virtual

2:09.1

Box.

2:10.2

And what's being delivered here is actually about 280, I believe, megabytes of code.

2:20.6

So the hypervisor, so virtual box is being delivered.

2:25.0

In addition to then the disk image with micro XP.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.