ISC StormCast for Wednesday, March 22nd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 March 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, March 22nd, 2017 edition of the Sands and its Storm Center's |
| 0:06.4 | Stormcast. My name is Johannes Ulrich and I am recording from Jacksonville, Florida. |
| 0:12.6 | Password encrypted Mavre is apparently back again. Now, in this case, it's a VIRT document. It is |
| 0:19.9 | encrypted using VIRT's own build-in encryption scheme. |
| 0:24.8 | The password that is required to decrypt the document is included in the email. |
| 0:32.1 | Now this is nothing new and there have been some anti-malvert tools that scanned the text of emails for passwords |
| 0:40.6 | in order to decrypt these emails. |
| 0:44.8 | Now, not sure how effective this is in this particular case. |
| 0:48.3 | Of course, if you just have the attachment, then you will have a hard time analyzing it. |
| 0:53.9 | And if you just upload the attachment itself, |
| 0:57.4 | a two-by-ris total, for example, you won't get any hits because each email is encrypted using |
| 1:04.8 | an individual password. Now, once you decrypt this particular word document, then you'll end up with the typical |
| 1:12.3 | JavaScript downloaders that will attempt to download various additional matter. |
| 1:18.8 | Of course, to a user who isn't familiar with this particular technique, a password encrypted |
| 1:24.0 | file may actually appear more trustworthy because apparently it is secure |
| 1:29.0 | by being encrypted with a password. And password wallet last pass fixed a rather serious vulnerability |
| 1:37.8 | in its Chrome extension. Due to a bug in the JavaScript that was delivered with this Chrome extension, it was possible |
| 1:48.1 | for an attacker to not only have direct access to the internal API for LastPass, which |
| 1:55.6 | essentially provides access to usernames and passwords, but also to execute arbitrary commands on the host system. |
| 2:04.9 | As an example, Project Zero has released a little proof of concept that will start the calculator |
| 2:12.8 | on your Windows system. This, however, will potentially also affect other operating systems, |
| 2:20.7 | not just Windows. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

