ISC StormCast for Monday, January 11th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 January 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 11th, 2021 edition of the Sand Center Storm Center's Stormcast. |
| 0:07.4 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.6 | Reverse engineering Malva is, of course, often shrouded under this mystery of reverse analysis of machine code and the like, and probably our reverse |
| 0:25.9 | analysis of malware and our intrusion detection classes are sort of our truly technical |
| 0:31.1 | defensive classes. But we do have a nice set of diaries by DDA from this weekend about demystifying this process |
| 0:42.0 | somewhat and coming up with simpler methods to figure out what Malver may potentially be doing. |
| 0:50.7 | By quickly, well, looking for interesting strings. |
| 0:54.1 | And DDA, of course, has a tool to make this easier. |
| 0:57.8 | His strengths dot p.Y tool, so he's running through a couple use cases there. |
| 1:02.8 | And before you say, hey, you know, there's possible of false positives, false negatives here, all true. |
| 1:08.7 | But personally, I find these methods really helpful for initial |
| 1:13.5 | triage of Malver. Before I figure out that a Malver is actually worth the hours of reversing, |
| 1:20.8 | because honestly, 99% of the Malver that you'll see are just small variations of malvern that you probably have looked at |
| 1:29.2 | before. And often I'm talking about research projects that are being presented. Like, for example, |
| 1:37.2 | Friday we had another science study student, but also research papers and such being published |
| 1:43.3 | by other universities. |
| 1:45.9 | But for a change, I have actually a paper where they are still waiting for input. |
| 1:52.7 | And I think the topic is really interesting and important. |
| 1:56.3 | So I would like to give them a little bit more exposure here. |
| 1:59.6 | It's not an easy survey to fill out. |
| 2:03.1 | And well, doing good surveys is actually quite difficult. |
| 2:08.0 | In this particular case, they're trying to figure out how reliable is the CVSS score. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

