ISC StormCast for Monday, February 10th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 February 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, February 10th, 2020 edition of the Sansaunt, Stormstar, Stormcast. |
| 0:07.4 | My name is Johannes Ulrich. |
| 0:08.8 | And I'm recording from Jacksonville, Florida. |
| 0:13.4 | So he came across an interesting visual basic script that he's talking about in a diary that he wrote this weekend. |
| 0:20.7 | Now, what's sort of interesting about this script diary that he wrote this weekend. |
| 0:20.9 | Now, what's sort of interesting about this script is that it incorporates a number of tricks |
| 0:26.7 | to detect whether or not it's running inside a virtual environment or a sandbox. |
| 0:32.6 | Now, none of these tricks are specifically new, but it's sort of neat to see them all in one single malicious |
| 0:39.4 | script. For example, this script checks whether or not the system it's running on only has |
| 0:45.7 | one CPU core. Pretty much any real system, and I think you actually would have a hard time |
| 0:52.0 | buying a physical system with only one CPU core. |
| 0:56.5 | So running only one CPU core makes you suspicious, say, having only one gigabyte of RAM or |
| 1:02.6 | less than 60 gigabyte of hard disk space. But often researchers, when they are running |
| 1:09.4 | a malware in a virtual machine in a sandbox, |
| 1:12.7 | they're assigning minimum resources to this sandbox to be able to run multiple experiments |
| 1:18.3 | at the same time. |
| 1:19.9 | And technically from a performance point of view, that's not a problem, but this particular |
| 1:24.3 | malware will not run. |
| 1:26.4 | It will also check for a number of common tools that |
| 1:31.0 | researchers are using to collect information about the malware. They're investigating like, |
| 1:36.5 | for example, good old Olli debug and similar tools. There's a whole list here that |
| 1:43.8 | Xavier found in this particular malware. And if you're |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

