ISC StormCast for Wednesday, February 3rd, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 February 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, February 3, 2021 edition of the Sandstone Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.4 | Xavier today took a look at a malicious Word document that was submitted by a user. Now, Brad looked at the traffic from that particular document. |
| 0:25.7 | So basically, he did the dynamic analysis. |
| 0:28.2 | And now from Xavier today, we do get the static analysis. |
| 0:32.6 | There's actually walking us through the macro being used here. |
| 0:37.2 | Kind of interesting, the macro being used here. |
| 0:44.5 | Kind of interesting, the macro first dumps an XSL file and XML style sheet, |
| 0:49.5 | and that actually then contains the code that is being executed. |
| 0:56.6 | An execution, well, that leads then to additional malware being downloaded in this case a version of Quagpot. Also interesting, Xavier's analysis does reveal what appears to be |
| 1:04.6 | the author's name, Alex Petrenko, at mail.r.U. |
| 1:12.8 | And starting in April, which should be Google Chrome 90, the Spanish Certific Authority, |
| 1:20.1 | comma, Fima, will likely no longer be included in Google Chrome. |
| 1:25.9 | We only had a handful of cases like this where certive authorities |
| 1:30.3 | had been revoked, and Google has documented a number of violations of standards that set |
| 1:38.7 | of authorities have to comply to with a comma firm. Whether or not other browser makers will follow Google's lead is still |
| 1:47.7 | somewhat open. Mozilla is debating currently whether or not they should accept a remediation plan |
| 1:55.0 | that KamaFerma did present. On the other hand, KamaFerma only issued 8,000 certificates so far, so the impact |
| 2:05.3 | should be rather minor. And of course, in the past, this entire set of authority ecosystem |
| 2:11.9 | has been the weak point when it comes to TLS, much more so than any TLS weaknesses in algorithms. |
| 2:20.4 | And in recent years, browser makers had attempted to be more stringent with certificate |
| 2:28.0 | authorities that do violate common required practices. |
| 2:34.6 | And remember, a couple weeks ago, we had Billy Wilson, a Sandsdot EDU student, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

