meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 31st 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 31 March 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. PowerShell EncodedCommand; GitHub Developers Targeted

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 31st, 2017 edition of the Santonet Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida.

0:13.0

Quite often useful features that are being added to software are being used against you by the bad guys.

0:20.9

Latest example that Xavier shows here is the encoded command feature in PowerShell,

0:28.8

which allows you to execute, for example, base 64 encoded strings.

0:34.7

This is of course useful because it allows you to transport these strings safely

0:40.3

through different channels, but then again it can also be used by bad guys to obfuscate their code.

0:48.3

And simple strings that are often being used to detect malware like SystemNet Webclined or download file and

0:55.5

the like are then really just converted into sort of randomish-looking characters.

1:02.6

Now, some anti-malware, of course, will decode it, but yet more work that you ask your

1:08.1

anti-malver to do.

1:10.1

So it may be worthwhile as Xavier suggests to just look for the encoded command string.

1:15.5

Well, and this may actually work quite well if it wouldn't be for another useful feature in PowerShell

1:21.8

that allows you to abbreviate commands.

1:24.8

For this particular encoded command argument, there are as one commoner

1:30.9

pointed out about 15 different versions to write it. It can be as simple as just the letter

1:37.7

E or E C or E.N and then essentially just any number of letters from the encoded command string.

1:47.0

And Palo Alto has documented pretty interesting

1:51.6

semi-targeted matter campaign.

1:54.6

In this particular case, I call it semi-targeted

1:58.5

because it wasn't really targeted

2:00.0

at a specific organization,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.