4.9 • 696 Ratings
🗓️ 29 August 2016
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, August 29th, 2016 edition. |
0:05.1 | Sandtonet Storm Center's Stormcast, my name is Johannes Ulrich, and today I'm recording from |
0:09.8 | Jacksonville, Florida. |
0:11.0 | I've got a couple diaries this weekend with obfuscated JavaScript. |
0:15.0 | First one was yet another Lockheye variant I wrote about on Friday. This one arrived in emails entitled |
0:23.8 | with a subject of office equipment and then it included a SIP file that was your usual |
0:31.2 | JavaScript file that then downloaded the actual malware. Sadly, a lot of antivirus still |
0:37.2 | does a bad job recognizing this, |
0:40.3 | even though if you have a very simple rule, just quarantine all-sipped JavaScript. You pretty |
0:47.7 | much can eliminate this threat from your environment. |
0:51.4 | In today, Guy reported about similar similar malicious email, also JavaScript, again, |
0:57.9 | that was heavily obfuscated. |
1:00.4 | He got a little bit more detail out of it with the JavaScript purifier, but still needs |
1:05.7 | a little bit more work to actually figure out what it is trying to accomplish. |
1:09.8 | I think a lot of individuals still have the perception that JavaScript is limited to some form of sandbox. |
1:16.8 | That's true if you download it in your browser, but once you have to file sitting on your system and you launch it locally, |
1:24.9 | that sandbox really doesn't apply anymore and JavaScript is able to just |
1:29.8 | download edition files. |
1:32.3 | And then we got an update for OpenSL, OpenSL 1.0.2H and 1.1.0.0.0.0.0.0.0. This is the first production |
1:43.0 | quality release of the 1.1 branch of OpenSL. |
1:47.0 | There is no need to immediately upgrade to 1.1.1.0.2 will continue to be supported for a while. |
1:56.0 | The big headline here is that this release does mitigate the Suite 32 attack. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.