meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, June 5th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 5 June 2020

⏱️ 13 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Anti-Debugging; Feed Update; Bank Transaction Spam;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, June 5th, 2020 edition of the Sandcent Storm Centers, Stormcast.

0:07.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.6

Xavier did a quick write-up today about a new technique that he has seen by matter to detect debuggers and that's guard pages. Guard pages are memory

0:24.7

pages that have the page guard flag set and whenever these pages are accessed then a status

0:33.6

guard. Page violation exception is triggered. So this can be used to detect if or if not

0:40.5

there is a debugger present and the malware can then react respectively. So for more details,

0:48.1

take a look at Xavier's diary. And then we got a couple of updates to our data feeds.

0:55.5

First of all, I had to suspend our suspicious domain feed, which I know is quite popular.

1:02.3

But the problem was that in recent months, some of the feeds that this feed, which is really

1:09.2

just an aggregate of different other feeds,

1:12.0

so relied on, have really degraded and become less and less useful.

1:16.7

Peter from DNS filter noticed this and notified us.

1:20.9

So I decided for now it's better to just suspend this feed.

1:26.3

We are working on trying to resurrect it with different input

1:30.8

feeds, but it may take a while to get it all set up. If you have any feedback or any sort of

1:38.0

feats you would like us to base it on, please let us know. And also I added more researcher IPs to our research feed that you can

1:48.6

request via our API. About 150 different IP addresses that are part of IPIP.net have seen them

1:57.0

scan quite a bit in recent times. So you will now have these IP addresses included as well.

2:05.8

Now, if you haven't heard of IPIP.net, it's probably because the company is based out of China.

2:11.0

Now, they do have somewhat global ambitions, but outside China, it's probably usually maximized what people are using

2:19.7

for geolocation services.

2:23.5

And remember how at one point there were proposals out there where spammers would essentially

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.