ISC StormCast for Tuesday, September 20th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 September 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, September 20th, 22nd2 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.3 | Malware arriving in the form of isophiles isn't new, but sadly it's still spreading fast. Tom observed a significant |
| 0:23.9 | uptick in the infections with the chrome loader malware, which initially arrives as an |
| 0:30.9 | isophile. Typically, the user is confronted with the malware after clicking on a malicious |
| 0:37.0 | search result, so that's where the author of the malware after clicking on a malicious search result. So that's where |
| 0:39.3 | the author of the malware uses search engine optimization to make links to the malware rank |
| 0:45.4 | high for specific popular keywords. After the iso file is downloaded, the user will then launch |
| 0:53.5 | the malware by clicking on a Properties. |
| 0:56.0 | Bad file that is included in the ISO. |
| 1:00.2 | Now, Tom is including more details in the diary, but the end effect is that the user ends up |
| 1:06.8 | with a malicious browser extension that will, in its simplest form, inject malicious ads. |
| 1:14.8 | But the real question that Tom is trying to answer, how do you prevent all of this from |
| 1:20.5 | happening in the first place? In Windows, you're able to block automatic mounting of iso files |
| 1:26.9 | either via group policies or registry settings. |
| 1:31.4 | Probably a good thing to configure this as I do not see a lot of legitimate software that arrives as an isophile |
| 1:39.5 | unless it is actually, well, of course, a physical city or DVD, if anybody is still using that. |
| 1:46.3 | One important exception I just want to point out in some Sands classes, we use isophiles to store the virtual machines. |
| 1:54.5 | It doesn't happen that much anymore, but I still think some classes are doing it. |
| 1:59.1 | So a little bit of a throwback from the days when we actually had DVDs for some of |
| 2:04.7 | these virtual machines. |
| 2:07.1 | Also, Tom isn't the only one noticing the search in Chrome Loader attacks. |
| 2:13.0 | Red Canary, Microsoft VMware, they all had similar warnings for the most part again. It just displays ads, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

