4.9 • 696 Ratings
🗓️ 6 February 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, February 6, 2020, 23 edition of the Sands and its Storm Center's |
0:08.3 | Stormcast. My name is Johannes Ulrich and I am recording from Jacksonville, Florida. |
0:15.1 | Analyzing large numbers of mal-resample is always a challenge and of course scripting here is the tool that |
0:23.2 | you're typically using in order to distinguish just the run of the middle kind of boring malware |
0:29.5 | from the interesting one that may deserve more attention and that's the kind of triage that |
0:37.2 | assembly line is kind of good for. |
0:40.2 | Guy wrote up the tool. |
0:42.0 | The tool itself was created by the Cyber Center Canada and well it's Docker container |
0:49.6 | essentially it's deployed in Docker that will allow you to upload malware to the assembly line system |
0:57.8 | and then essentially trigger various analysis tools. Some of them commercial, some of them |
1:04.7 | open source, and all of them are then summarized in a report. Now you can also make some of these decisions |
1:14.3 | kind of depend on what a particular tool finds |
1:17.1 | or what kind of malware you have. |
1:20.3 | Like I said, it sounds like a pretty interesting system |
1:23.3 | to sort of do your initial triage in particular, |
1:26.9 | since this looks like it's much more easy to maintain |
1:31.4 | than some of the alternatives. |
1:35.9 | And Brian Grebs posted on Mastodon about an advisory published by Fortra. |
1:42.2 | Fortra is the maker of Go Anywhere MFT. MFT stands for managed |
1:47.5 | file transfer, a solution that companies use for sort of internal controlled file transfer. |
1:55.1 | The problem here is remote code execution vulnerability and the advisory that the Fortra published hasn't really been |
2:06.5 | accessible publicly. You have to log into the customer portal. Now Brian Grabs posted a part of |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.