ISC StormCast for Wednesday, December 20th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 December 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, December 20th, 2017 edition of the Sandcent Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and today I'm recording from Washington, D.C. |
| 0:12.9 | Microsoft PowerPoint documents do offer a number of ways to trigger code execution. |
| 0:20.4 | Now, typically, we are used to that we have to click on a link in order to cause damage. |
| 0:25.6 | And one common trick to figure out where a link leads you is typically just to hover the mouse over it. |
| 0:33.6 | Sadly, PowerPoint does have a feature that allows you to trigger code execution |
| 0:40.3 | based on the mouse over event. So in this particular case and Xavier just ran into a sample |
| 0:47.3 | of this particular trick, you do execute code just by hovering the mouse over the link. |
| 0:55.0 | I'm pretty sure I mentioned this technique before. |
| 0:58.0 | It's certainly not new, but it hasn't really been seen much in actual malware so far. |
| 1:06.0 | About a year ago, I reported about adware that came pre-installed in some low-cost Android phones. |
| 1:15.1 | It was really more than adware. It was really more spyware. Collected an awful lot of |
| 1:21.0 | information about the user and also sort of implemented a back door. It became known as ad-ups back then. |
| 1:30.2 | And the difficulty here was that it came pre-installed on the phone, |
| 1:34.3 | which made it kind of impossible to uninstall it. |
| 1:38.3 | Well, ad-ups is back. |
| 1:40.5 | They now changed their name a little bit. |
| 1:43.6 | They call it now Fw upgrade a provider which i |
| 1:46.8 | guess is supposed to sound like a firewall but well it's just the opposite it again does |
| 1:54.3 | exfiltrate user data and has the ability to install additional code on the phone apparently some of the standard techniques to disable it are also failing on this new |
| 2:05.9 | version. |
| 2:07.1 | If you do have an affected device, there isn't really much help at this point. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

