meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, June 30th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 30 June 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Phish Without Link; June Contest Solution; WD MyBook Details; Adobe Experience Manager PoC;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, June 30th, 2000, 21 edition of the Santernut Storms,

0:06.4

on a stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:13.1

Our Handlery Jing came across an interesting email that claimed to come from Google and

0:18.3

tried to entice victims to send them their personal information.

0:23.8

So it was sort of a fishing attempt, but a little bit different sense that, first of all,

0:29.2

there was no link involved here.

0:32.1

Instead, there was just a PDF, which, well, I guess, sort of looked legitimate like it came from Google.

0:40.0

Lots of random codes and such and colorful background logo in order to exfiltrate the information.

0:49.7

What the attacker did here is basically just list all the information they need in order to release this

0:56.6

payment to you and then email it to a particular email address. They went as far as to

1:03.3

register a domain, G-O-O-Corpret or corporate really.com. So something that looks a little bit like it could be used

1:13.4

by Google for corporate purposes like this. The domain was registered last September, so not

1:21.9

terribly new and interesting kind of to see whether or not anybody would fall for a trick like this.

1:30.7

But this is the type of trick that's not really all that easy to prevent by just filtering or scanning email,

1:39.2

because there wasn't really sort of anything terribly wrong with this particular PDF.

1:45.8

And Brad posted the solution for this month's forensics contest.

1:51.1

So if you were working on this or if you submitted a solution, well, you can now check if you

1:57.7

got it right.

1:58.5

I think we only got like five totally completely correct

2:03.4

solutions in total is what Brad told me I know we got a ton of submissions say

2:10.1

even though this one was significantly more difficult than some of the

2:15.5

prior quizzes that Brad posted.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.