meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 22nd, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 January 2021

⏱️ 14 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. PS RunSpaces and REvil; SAP Exploit; Oracle Patches; RDP DDoS; High Performance Computing @sans_edu

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, January 22nd, 2021 edition of the Sandcent Storm Center's

0:07.5

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:14.2

Diary today from Xavier talking about a power shell script that he ran into that will load the R. Evil Ransomware,

0:23.5

but it does so using a PowerShell script feature called Run Spaces, which isn't often seen

0:30.2

in Malware and apparently here used to evade some of the detection techniques.

0:36.6

And also this particular script had a very low

0:40.2

virus total score. Run spaces are well sort of containers, I guess you could call them,

0:46.5

that isolate different power shell threats from each other. They all run in the same power shell process, which makes a little bit more efficient

0:57.7

than having multiple power shell processes running instead.

1:03.3

In this case, it also helps with obfuscating the code.

1:06.6

One of the run spaces is then decrypting additional code using a key that is passed to it as a variable.

1:16.6

This diary also comes with a warning from Xavier.

1:19.6

Xavier analyzed this piece of malware in his lab, which is isolated from the rest of the network.

1:26.6

And this turned out to be quite useful in this case, because as he was analyzing the malware

1:32.7

as typical when doing runtime analysis, he set a couple of breakpoints to figure out how

1:39.1

the malware operates, but well, forgot one.

1:42.0

And actually, his lab machine ended up encrypted by the ransomware.

1:49.0

Not a big deal for a lab machine, of course.

1:51.3

Well, now you have to recover it, but I have seen this go wrong quite often before where

1:58.6

analysts weren't careful enough and losing real work or even leaking

2:04.4

data by running malicious code on a regular work machine.

2:10.9

And researchers at Onypsis found posted on GitHub a functional exploit that takes advantage of a vulnerability in SAP's

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.