4.9 • 696 Ratings
🗓️ 6 December 2021
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, December 6, 2021 edition of the Sansonet Storm Center's Stormcast. |
0:08.0 | My name is Johannes Ulrich. |
0:09.8 | And today I'm recording from Jacksonville, Florida. |
0:13.9 | Xavier today has a quick diary about a piece of malware that he found that uses the good old |
0:19.2 | UPX packer. UPPS is, well, not really |
0:23.2 | malicious. It's intended to be a quick way to compress binaries that are then able to |
0:30.1 | self-unpack as the user runs the binary. But of course, that's also quite helpful for |
0:37.0 | attackers. And over the years, |
0:38.8 | attackers have made small changes to the original UPX algorithm in order to create |
0:45.3 | intentionally incompatible implementations that make reverse analysis a tiny little bit more |
0:52.4 | difficult. I remember, I think it was like 15 years ago or so, |
0:57.0 | Tom Liston wrote like a little tool for us that he packed with UPX just to basically |
1:04.3 | arrive at a smaller binary. And back then, actually, some antivirus tools just flagged it |
1:10.4 | because it used UPX. |
1:12.9 | Well, Xavier walks you through how to analyze a binary that is packed with UPX. |
1:19.4 | Of course, often you can just essentially decompress it using one of the freely available UPX command line tools. |
1:28.9 | And ESAD took a look at tags against air gap networks, at least at hacks that have become |
1:35.8 | public, so where there is some detail available about how did hack exactly evolved. |
1:41.8 | Well, probably not a big surprise, but as far as techniques go in order to bridge |
1:47.1 | the air gap, there isn't much about blinking LED lights or the sound of spinning fans or any of |
1:54.4 | these very theoretical methods that, of course, always sort of make the news big times when a |
2:00.6 | researcher demonstrates |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.