meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, August 30th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 August 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Malware Compiling Itself; Notifying Vulnerable Home Automation Owners; Botnet Takedown

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, August 30th, 2019 edition of the Sansonet Stormsendos Stormcast.

0:07.4

My name is Johannes Orich, and I am recording from New York City, New York.

0:12.7

Typically, on Windows environments, you don't find compilers by default, unlike on many Unix environments so malware as a result

0:23.6

often arrives pre-compiled as an executable. Xavier found a couple of exceptions

0:31.6

of this behavior and they rely on JSC.exe. Thate. That's a jScript compiler that is part of the dot net framework.

0:44.0

And while most Windows systems do have dot net framework installed, with that they have jsc.org

0:51.7

installed. They also then typically have MSBuild.exe installed, which actually allows

0:58.0

you to automatically build applications similar to the make command in Unix. And while it doesn't

1:05.6

happen often, Xavi ran across a couple samples that took advantage of these tools.

1:12.1

Most likely the purpose here is to, again, obfuscate the attack, to evade antivirus

1:18.2

scanners because they usually only look for the executables, they don't look for the source

1:23.8

code.

1:24.8

In this case, actually, the code was delivered, Base 64 encoded,

1:29.3

probably to make it easier to transfer, but also possibly to further obfuscate it.

1:35.3

Now, As Xavier points out, jsc.exe and MSbill.exe, yes, they are on pretty much all corporate

1:43.8

machines because they all have the dot-net framework

1:46.1

installed, but they're not usually used.

1:49.3

So these are two indicators that you can use to detect possible malicious behavior if these

1:57.7

two executables are run on a system in your network.

2:04.4

Now, if you are into home automation, there are typically kind of two ways how you can control

2:11.3

your home automation system while you are away from home.

2:15.2

And that's often one of the attractive features here.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.