ISC StormCast for Wednesday, August 30th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 August 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, August 30th, 2017 edition of the Sands and its Storm Center's |
| 0:06.5 | Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:12.5 | Now, Renato found another piece of banking malware that's implemented as a Google Chrome extension. |
| 0:19.5 | While the earlier one that he found sort of a week ago, it was |
| 0:23.1 | advertised via phone calls, this one arrives more typically in an email. Now, the way they sort of |
| 0:30.7 | get people to actually click on the email is by claiming that it is a termination notice from their employer. |
| 0:39.4 | The initial email actually looks very much like a lot of other malicious emails that are |
| 0:44.9 | being received these days. It's a SIPD Visual Basic script. And that may be why they're |
| 0:51.0 | flying a little bit under the radar because these kind of |
| 0:54.2 | SIPD Visual Basic scripts are so common, it's hard to analyze them all. |
| 0:59.4 | Now the other sort of little twist here is that the downloader that's implemented with this |
| 1:04.6 | visual basic script does already detect whether it's running on a virtual machine. |
| 1:10.0 | Typically I've seen this being done |
| 1:11.9 | later down the row in the infection chain. If you are a virtual machine, then all you get |
| 1:18.5 | back is a non-malicious JPEG file. However, if you are not running in a virtual |
| 1:24.7 | machine, then further malware will be downloaded that will then |
| 1:29.7 | install the Chrome extension. Once it is installed, this extension that calls itself ID key store |
| 1:37.5 | will monitor all network connections that are established with Chrome and exfiltrate authentication data. |
| 1:45.0 | Now, Renato lives in Brazil and the particular Malaray that he looked also had a very specific |
| 1:52.0 | Brazilian feature in that it intercepted what they call bolitos. |
| 1:57.0 | That's a compensation ticket that you issue to customers. |
| 2:01.6 | So if someone is issuing one of those tickets, which is really just a barcode, it will send |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

