ISC StormCast for Wednesday, August 17th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 August 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, August 17, 2020 edition of the Sands and the Storm Center's |
| 0:07.6 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.1 | Today we got yet another great post by DDA walking us through the analysis of a malicious office document. |
| 0:23.4 | D.D.E. uses his tool Olli D.D.A. to extract the visual basic for applications code, |
| 0:30.7 | but while as so often the code was heavily obfuscated, as part of the obfuscation, the script |
| 0:37.4 | calls multiplied to white char, |
| 0:41.1 | a function that allows conversion of bytes into characters by specifying and encoding. |
| 0:47.7 | Now, typically, you would find something like UTF8 or UTF 16, but not so. |
| 0:54.5 | Here, the attacker actually picked the rather ancient UTF7. |
| 0:59.7 | Back in the day, I remember disencoding sometimes led to the bypass of some cross-side scripting filters, |
| 1:06.3 | but here UTF7 is just used to full anti-malware tools to ignore and not being able to really figure out what's happening here. |
| 1:15.7 | Well, not so, of course, with the help of DDA. |
| 1:19.2 | DDA isn't fooled so easily, and he'll walk you through decoding these scripts. |
| 1:25.9 | The output is binary code, followed by some assembly source code, which actually doesn't |
| 1:32.2 | really make sense, and the Deere guesses that the assembly source code was just left by mistake. |
| 1:40.0 | Now, the shell code, DDE was able to analyze a 64-bit code, |
| 1:45.8 | and that finally revealed then a URL |
| 1:49.4 | that may be used to load additional code. |
| 1:52.6 | So pretty thorough walkthrough here of some interesting |
| 1:56.5 | and somewhat unusual sample. |
| 2:01.0 | And Microsoft recently went after a threat group that they're calling Cyborgium, and that is |
| 2:08.8 | likely aligned with Russian interests. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

