meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 1st 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 1 October 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Maldoc, Powershell and BITS; Cisco Patch Cycle; Exim Flaw

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, October 1st, 2019 edition of the Sandsenet Storms and a stormstormcast. My name is Johannes Ulrich. And the time I'm recording from Jacksonville, Florida.

0:13.9

The here today is walking you through the analysis of a malicious office document. It actually arrived, encrypted, and then used PowerShell in order to download its actual

0:26.9

payload via bits.

0:28.9

It's a little bit of follow-up to a diary that the DA posted this weekend.

0:34.5

And what was sort of interesting about the sample initially was that the password

0:39.1

mentioned in the email actually turned out to be wrong.

0:44.5

But in this analysis, DDA is using the correct password for this particular document and

0:52.7

then was able to extract the PowerShell script that this document

0:58.1

attempts to execute.

1:00.0

Now the use of bits is nothing new.

1:02.5

Bit stands for the background intelligent transfer service.

1:06.7

That's sort of the closest thing to W. Get and Curl that you find on a Windows system, and

1:12.7

the nice part about it is that it's a standard systems component used to download updates,

1:20.1

so it wouldn't be all that unusual to see Bits with its fairly characteristic user agent

1:26.9

reaching out, outbound.

1:29.3

Now, some people saying that, hey, Bits is only really used by Microsoft so you can look

1:34.3

that it doesn't reach out to any non-Microsoft IP addresses.

1:39.1

Not really true.

1:40.1

I have also seen Bits being used by other legitimate software to download updates. But anyway, if you

1:47.1

want to follow DDA's analysis, he did put together as a step-by-step guide as to how he

1:54.8

analyzed this particular document. And the XIM mail server is the gift that keeps on giving for the bad guys, yet another

2:06.3

vulnerability in the XMail server, yet another remote code execution issue.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.