meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, September 5th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 September 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Locky Back Via Fake Fonts; Asterisk RTPBleed; Arris AT&T Backdoor

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, September 5th, 2017 edition of the Sansanet Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich, and I am recording from New York, New York.

0:11.0

We've got a couple of diaries to catch up here from this long weekend.

0:16.0

The first one actually is from Friday about a new variant of Locky. Now, Locky has been back the last

0:24.1

couple of weeks. The latest variant is in particular tricky in the way it sort of tricks

0:29.6

users into installing the ransomware. It arrives as a fake Dropbox message that's actually

0:36.0

done quite well. If you click on it, you're then asked

0:39.6

to open an update notification, which then instructs you to install what it calls a Heffler font.

0:47.3

So essentially, the user here believes that in order to read the message, they have to install

0:51.5

this font. Fonds, of course, are usually not considered to be executable or malicious, but what you

0:57.6

are actually downloading is an executable that will then download additional malware, including

1:04.3

the actual ransomware.

1:06.8

So nothing really fundamentally new as far as exploits go, but really sort of a new social

1:12.5

component to this particular version of Locky.

1:16.8

Now, Brad tried to run it in different browsers, and it appears to adjust itself to

1:22.0

different browsers, but he had some mixed results here.

1:25.6

It didn't actually always run all the way to install the ransomware.

1:30.5

But again, then this may be just the fact of one or two of the domains that are being involved here

1:35.7

being already shut down by the time that he ran this particular sample.

1:40.8

Now, one of the most difficult parts in security is to figure out if a particular system is not infected or a particular file is not malicious.

1:50.0

Didier is taking a stab at this task and he is now two parts into his, I believe, three-part diary.

1:59.0

First two parts, he hasn't really found anything yet in this particular PDF.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.