ISC StormCast for Wednesday, October 4th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 October 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 4th, 2017 edition of the Sands and at Storm Center's |
| 0:06.5 | Stormcast. My name is Johannes Ulrich and I am recording from Jacksonville, Florida. |
| 0:12.4 | Depending on how well your spam filter works, you may have noticed a recent increase in FedEx |
| 0:20.0 | shipping notification scam emails. |
| 0:22.3 | Now the attachment here is actually not crypto ransomare for a change in Stead and |
| 0:29.8 | Brad wrote this up today. We do have form book being downloaded. |
| 0:35.7 | Formbook is a newer information stealer malware and what's kind of unique about it is that it was written without the use of any standard Windows API. |
| 0:46.3 | A lot of anti-malver triggers whenever a piece of software tries to, for example, take a screenshot or intercept keystrokes using |
| 0:55.8 | standard Windows APIs. Well, in this case, actually, it all does it sort of from scratch, |
| 1:03.3 | so it never calls these Windows APIs, making it a little bit more difficult to identify for |
| 1:09.6 | anti-malvert. Not having sure why people are still falling for these FedEx shipping notices, but then again, |
| 1:17.2 | this may be targeting retailers and such for point of sales compromises who do receive |
| 1:25.0 | quite a bit of shipments and such via UPS and FedEx and maybe expecting something |
| 1:30.2 | so they may not be that aware that this isn't actually a valid shipping notice. |
| 1:38.8 | And while we're sort of at the public service announcement stage here, WordPress. |
| 1:45.0 | Yes, you probably know you probably shouldn't run it. |
| 1:48.0 | If you do have to run it, then definitely keep it up to date and don't forget the plugins. |
| 1:54.0 | The latest reminder comes from WordFense, of course a company that does provide security |
| 2:00.0 | tools for WordPress and they're just |
| 2:03.8 | documenting how in particular vulnerable plugins are being exploited to take over sites. |
| 2:11.7 | What you can expect happening then is actually often not an outright defacement of the site, but information about your users |
| 2:21.0 | may get stolen and also new pages may get at it that are then used, for example, to distribute |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

