meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Monday, March 2nd, 2026: Reversing Fake Fedex; Abusing .ARPA; MSFT Authenticator Update; Apex One Vuln; Special AirSnitch Webcast

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 2 March 2026

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Monday, March 2nd, 2026: Reversing Fake Fedex; Abusing .ARPA; MSFT Authenticator Update; Apex One Vuln; Special AirSnitch Webcast

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, March 2nd, 2006 edition of the Sands Inlet Storm Center's Stormcast.

0:12.0

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:16.1

And this episode is brought you by the Sands.edu undergraduate certificate program in applied cyber security.

0:24.7

In Diaries this weekend, we had one by Xavier about, well, a fake FedEx email.

0:30.4

The problem with these FedEx emails are to many of us.

0:34.7

They're kind of old news and, you know, it's easy to recognize.

0:39.3

But think about it from perspective, not sort of how I've seen these emails work of someone that receives

0:43.3

a lot of or a reasonable number of these FedEx emails,

0:46.3

they're dealing a lot of shipping,

0:48.3

they're sort of a little bit desensitized to that,

0:50.3

and then maybe tricked, like in this case,

0:52.3

to opening an attachment that is actually

0:55.5

a 7-zip file.

0:58.9

Xavier walks you through the analysis of this particular malicious email, starts out with a

1:05.0

simple batch file and also usual sort of persistent mechanisms, then encoded PowerShell script. In the end, it's actually an

1:14.4

AES encrypted script. Of course, the credentials here keys and IVs are in the binary, so in that

1:21.6

zip file. So definitely something that you can then extract the order to decrypted.. And that's sort of what Xavier walks you through here.

1:30.9

The decryption part is probably sort of a more interesting and dangerous part in some ways, too,

1:35.9

because you, in this case, like, the easiest way to do it is just run the PowerShell script,

1:40.8

but then put the right break points in place.

1:43.1

So it really just decrypts it and doesn't actually execute it.

1:47.8

And the next stage, which in this case, well, turns out to be a script called donut loader.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.