ISC StormCast for Monday, August 1st, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 August 2022
⏱️ 9 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, August 1st, 2020 edition of the Sansanet Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.9 | We often cover analyzing malicious PDFs in our diaries. |
| 0:18.6 | In particular, DDA's tools are calmly used, but most of the time we walk |
| 0:23.7 | you through some specific feature or some particular interesting artifact. But what we have |
| 0:31.1 | been missing a little bit, I think, is to really sort of give you some of the basics in analyzing |
| 0:36.9 | these documents, which are all too common, of course. |
| 0:41.4 | On Friday, Jesse, who is our new apprentice handler here, went over a quick introduction to how to use PDF parser on a normal malicious PDF to explain some of the basic features of this tool. |
| 0:58.9 | So for everybody getting started with Malware reverse analysis, in particular PDFs, bookmark the post, |
| 1:05.3 | and follow Jesse's steps here to figure out how PDF parser works. |
| 1:13.5 | Well, of course, one way PDFs are sometimes used is fishing, but well, fishing, usually more |
| 1:19.7 | related to bad login pages for criminals attempting to find locations to host these files. |
| 1:27.3 | Well, they're cloud providers, and we of course have seen this a lot. They're very attractive option, but Trustwave and others have recently observed another option in increased use by attackers, and that's IPFS, the interplanetary file system, as it's called. |
| 1:45.5 | What it basically is is stores files on systems around the world. |
| 1:50.6 | It's a little bit sort of tour-like in that sense, but really just meant to store files. |
| 1:56.3 | The files are then identified by hashes, and to access a file, you may send an HTTP request |
| 2:03.6 | to a particular gateway. |
| 2:05.7 | Now, a user will just send a normal HTTP request |
| 2:09.8 | to one of those gateways. |
| 2:11.1 | Then often a number of redirects happen |
| 2:14.4 | until you end up with the file. |
| 2:17.2 | Part of these redirects is often there, the initial URL, which is the gateway, then at the end, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

