meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, December 12th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 11 December 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Malware Anti-Reversing Trick; #PwC ACE Makes #SAP Vulnerable;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, December 12, 2016 edition of the Sands Internet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and I am recording from Washington, D.C.

0:11.9

If you're interested in Malware Analysis, you probably realize that there is an ongoing game of

0:18.8

countermeasures and counter-ounter measures between Malver analysis

0:23.6

and Malver authors.

0:25.6

DDA has a nice example of one of those tricks.

0:30.6

Now Malware, when you analyze it, one of the simple ways to analyze Malware is just to run

0:36.6

it for a while.

0:38.4

Melva authors, of course, realize that, and they will just delay any actions for a while

0:44.0

in order to escape detections.

0:46.6

Because the analyst, for example, would like to figure out what are additional components

0:51.0

the Malware downloads.

0:52.4

Well, if the malware waits long enough, then the

0:55.7

malware analyst may miss those additional downloads. Then, of course, the analysts started to

1:03.7

accelerate the system clock on the system they're using to analyze the malware. Well, the next

1:09.6

step, and that's something DDA is talking about,

1:11.7

and he has seen that now even in some of these visual basic script samples that he was analyzing.

1:18.1

The malware will just look for an external time reference, like an NDP server,

1:23.6

try to connect to it, and then try to figure out how much time expired in real life compared to the

1:31.1

system time that way it will be able to first of all detect a large skew in system time but it will

1:38.2

also then just detect what the real time elapsed is and based on that again delay execution of course you can

1:46.7

still statically analyze the malver but that tends to be more labor intensive and time consuming

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.