ISC StormCast for Wednesday, November 6th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 November 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, November 6, 2019 edition of the Sanson, Storm, Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.2 | Brad wrote today about a malicious RTF document that's distributed as an email attachment, |
| 0:19.7 | and that's pushing formbook. |
| 0:22.6 | Formbook is a little bit different and so far that it's an information stealer. |
| 0:25.6 | It's going after passwords, so not the crypto coin miner. |
| 0:29.6 | We see all over the place these days. |
| 0:32.6 | And as usual, Brad has plenty of indicators of compromise, as well as links to the actual |
| 0:41.2 | malware and P-CAPs. |
| 0:43.0 | And well, I didn't get quite to write about it today because it's sort of took me a little |
| 0:50.3 | bit longer than expected, but I made a little bit a major update to the Honeypot |
| 0:57.7 | script that we are using. It's now updated to the latest and greatest version of Cowry. |
| 1:04.2 | Also, some issues people had with SSH not working correctly are now fixed, so at least I hope. |
| 1:13.0 | And it also does now fully work on Ubuntu 1804. |
| 1:18.9 | Of course it still works on the Raspberry Pi and that's still probably the most popular |
| 1:24.4 | platform people are using, but we had some requests to run these scripts |
| 1:29.9 | in a virtual machine that's often simpler than setting up a separate piece of hardware |
| 1:35.7 | if you already have a server to run virtual machines. So now just grab the latest |
| 1:41.5 | Ubuntu 1804 LTS server and it should work just fine on that. |
| 1:47.9 | The easiest way to learn more about this honeypot is just iSc.sand.edu slash honeypot.html. |
| 1:56.5 | And search.org released an interesting warning regarding an odd behavior of office documents on the Mac. |
| 2:07.6 | You are able to disable all macros without notification, which seems to be secure settings. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

