meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 13th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 13 October 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Nested MSG Files; Trickbot Takedown Attempt; Chrome Improving Cache Privacy

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, October 13th, 2020 edition of the Sandsenet Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:13.0

Yesterday I mentioned how the DEA went over his plug-in message summary tool that allows you to easier take apart Outlook message files.

0:24.9

Well, as it happens that readers of course are trying this out on different files and one

0:31.6

ran into an interesting, fairly complex file, at least that's sort of what it looked like, and DDA had a look to see

0:40.1

what's actually going on here. So what happened here was that the email that was inside the

0:46.3

message file actually had another message file as an attachment, and that leads to nested message

0:53.8

files that can be quite complex when you

0:57.0

sort of first look at all the list of components within the file.

1:02.0

Now, the day shows how to make sense of all of this data and in the end also how to quickly

1:09.0

extract the subjects for the affected emails,

1:13.4

which of course then already gives you some insight as to what exactly was contained in these

1:20.4

different files.

1:22.7

And it looks like a lot of interest is being paid to the Trickbot Botnet lately and the most recent action

1:31.3

was taken by Microsoft by obtaining court orders to actually disable IP addresses and trying

1:39.2

to disrupt the command and control servers that are responsible for trickbot.

1:46.5

Now, oftentimes, of course, it doesn't take that much effort, and ISPs will cooperate or domain

1:52.4

registrars and such, but once Botnet has sort of learned how to evade various tricks and found

2:00.1

essentially some form of bulletproof

2:02.5

hosting. Yes, it can get quite difficult and court orders and such are needed and Microsoft took

2:08.9

the lead because they felt also that some of their trademarks were violated by Trickbot, which

2:15.5

gave them some legal standing to obtain these court orders.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.