ISC StormCast for Wednesday, January 19th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 January 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, January 19th, 2020 edition of the Sands and it's Storms owners, Stormcast. |
| 0:08.3 | My name is Johannes Ulrich. |
| 0:09.8 | And today I'm recording from Jacksonville, Florida. |
| 0:13.4 | A good interesting fishing email today that Jan ran into now. |
| 0:18.4 | First, it's fairly standard. |
| 0:20.2 | It claims to be a fax received via a syrox scanner. |
| 0:25.3 | So often you have also seen this kind of lure being used for malware. In this case, however, |
| 0:32.0 | if you click on it, well, it redirects you to an Office 365 fishing page. |
| 0:38.0 | But what sort of made this email stand out more than the fact that it was sort of impersonating |
| 0:43.9 | that the Syrox scanner was that it actually also included an ad for Syrox. |
| 0:51.4 | Couple reasons for this. |
| 0:52.6 | First of all, I'm not familiar with this particular Syrox product. |
| 0:56.2 | They're impersonating here, but it's very possible that they do include ads like this, |
| 1:02.1 | so they're now just impersonating the complete email as it would show up from a legitimate source. |
| 1:10.6 | But it could also be a second way to essentially try to monetize |
| 1:16.3 | these phishing emails by adding some ads. |
| 1:19.3 | And well, maybe based on keywords in the email, |
| 1:22.0 | this was the ad, the ad network delivered for this particular email. |
| 1:27.1 | In general, this looked sort of like a fairly unsophisticated copy-paste job when it comes |
| 1:32.6 | to the phishing page. |
| 1:33.8 | They actually didn't get some of the JavaScript right and such to actually make it work |
| 1:39.0 | properly. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

