ISC StormCast for Friday, May 10th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, May 10th, 2019 edition of the Sancton Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.4 | And today I'm recording from San Diego, California. |
| 0:13.3 | The Department of Homeland Security released a brief analysis of Malware that it is calling electric fish, |
| 0:20.0 | and that is, according to the Department of Homeland |
| 0:23.2 | Security associated with North Korea. |
| 0:27.1 | Now like I said, it's pretty brief what they're writing up here. |
| 0:31.2 | There are some code samples, but overall the write-up isn't terribly clear in what sort |
| 0:37.1 | of makes this malware all that special. |
| 0:39.8 | It appears to be a simple backdoor essentially that can be used via a proxy system. |
| 0:47.9 | The backdoor is authenticated, but it uses its own static username and password, so it does not rely on any authentication provided by the operating system. |
| 1:00.5 | Now, I can think sort of a couple possible reason why a particular tunnel like this may come in handy. |
| 1:06.4 | First of all, it's fairly flexible as far as what port is being used. |
| 1:10.3 | Since it's not using a standard protocol, it may not get flagged by some application signatures |
| 1:17.0 | that will, for example, alert on SSH running on a different port. |
| 1:22.0 | Also, it's not using the operating systems authentication features, so it probably won't get locked whenever it is being |
| 1:30.3 | used. |
| 1:31.3 | And like always, with covert channels like this, once you do know what to look for, it's |
| 1:36.8 | actually not all that hard to spot. |
| 1:39.6 | This particular malware starts out with a static header that's being used to essentially identify and authenticate |
| 1:46.8 | then to the receiver. Only two bytes of this header are intentionally randomized. KeyPass is a pretty |
| 1:56.2 | well respected open source password manager. Now if you want to download KeyPass, you better go to |
| 2:04.5 | keypass. info. KeyPass.com, while it does look like a site associated with the password |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

