ISC StormCast for Friday, February 9th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 February 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, February 9th, 2020, |
| 0:04.0 | for edition of the Sandstone Storms, Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.8 | This is also the 15th anniversary of this podcast. |
| 0:19.5 | As I've said before, if you have any tips how to make this podcast better, |
| 0:25.8 | what you like, what you don't like about it, please let me know. That's really sort of how you can |
| 0:31.9 | pay back a little bit for the work that goes into making this podcast to make sure it's the best podcast that I could |
| 0:39.2 | possibly do, given the overall format of a short-form podcast like this. |
| 0:47.2 | Xavier today came across another interesting, and with interesting, we usually mean malicious |
| 0:52.1 | Python script. |
| 0:53.7 | This, again, is a Python script |
| 0:55.5 | with Gwi which always is |
| 0:58.3 | somewhat suspicious it's |
| 1:00.9 | attempting to be an MP3 player at least |
| 1:04.0 | that's what it says it doesn't it apparently also |
| 1:06.2 | works somewhat as an MP3 player but in addition |
| 1:09.5 | to being an MP3 player it but in addition to being an MP3 player, it'll also log keystrokes. |
| 1:14.3 | Xavier does have a little video with a walkthrough of the analysis of this particular script |
| 1:19.1 | to show how it works, and well, virus total, again, low score here, only two out of 61 antivirus engines are detecting this specific Python script as malicious. |
| 1:34.9 | Now, you may say why would anybody ever install a Python MP3 player? Like, particularly, if you look at the screenshots here, it doesn't really look like much. |
| 1:44.4 | One thing I'm a little bit worried about is that some of these applications |
| 1:49.5 | may be used sort of as sample applications by developers to basically learn how to do certain |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

