ISC StormCast for Friday, March 1st, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 March 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, March 1st, 2020, 4 edition of the Sands and at Storm Center's Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida. |
| 0:15.2 | Today we have a treat for everybody into Malvernalysis. And it's a diary by John John Mutos, one of our Sands.E.D.U. |
| 0:24.6 | bachelor's degree interns. The diary covers a recent instance of Darkgate. Darkgate, as John |
| 0:32.5 | describes, persistence as service Malware. The goal of DarkGate is to assist other malware to install on various systems. |
| 0:42.7 | So you can rent DarkGate if you need to install malware on systems. |
| 0:47.3 | In this particular case, it all started fairly harmless with a PDF. |
| 0:52.4 | The PDF itself was not malicious. |
| 0:54.6 | It just contained a link that then via double-click, interestingly, |
| 0:59.6 | so essentially as an ad, directed the victim to the actual malware that was then downloaded. |
| 1:08.3 | Now, there's too much detail here to cover it all in this podcast, but just a couple of highlights |
| 1:14.1 | here. |
| 1:14.9 | Part of the installer, for example, is a valid Apple binary iTunes helper.e. |
| 1:22.0 | Digually signed and everything and will pass all the sort of sanity checks, but it's delivered with two DLLs. |
| 1:30.6 | And these DLs are then where you find the malicious code that will cause additional Malver |
| 1:37.7 | to be installed. |
| 1:39.5 | So lots of interesting details here about this Malver and the very detailed analysis by John. |
| 1:45.7 | Like I said, if you are at all into Malvern analysis, you'll probably enjoy how he sort of walks you through the process here to identify the different parts of this Malver. |
| 1:57.4 | And the Cybersecurity and Infrastructure Security Agency CISA did a population update on some of |
| 2:05.5 | the exploits that they're seeing against Ivante Connect secure and the policy secure |
| 2:11.8 | gateways. I've mentioned the vulnerabilities a few times already, and yes, they have been exploited for a while. |
| 2:20.0 | There are a couple interesting tidbits I want to point out in this particular advisory, |
| 2:25.1 | and that's based on some of the compromise that have been seen in the wild. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

