ISC StormCast for Monday, January 29th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 January 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 29th, 2018 edition of the Sands Internet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.5 | Ever started investigating a suspicious email just to figure out that it was part of a pen test? |
| 0:20.2 | Of course, you often don't know until you did much of the analysis. |
| 0:25.9 | Now, D.D.E. is going over a case like this in his diary from this weekend. |
| 0:31.6 | And in this case, it was a Word document, not just a link to a web page as you often see him. |
| 0:37.8 | Did he was able to analyze the document quickly using his slick set of Python tools to extract |
| 0:46.0 | the text from the word document. |
| 0:48.2 | Now this text in his case was written in Slovak explained that this particular word document |
| 0:54.0 | was part of the |
| 0:55.0 | pen test. Of course you should still do a quick look and make sure that this is actually |
| 1:01.0 | a test and doesn't include any malicious payload. You could see an attacker use a text like this |
| 1:07.4 | to prevent this particular word document from being reported. |
| 1:12.6 | Now, when you investigate Windows malware, one tool often used to download additional documents |
| 1:19.6 | is the background intelligent transfer system, or bits for short. |
| 1:24.6 | It's part of the update system in Windows. For attackers, it plays a role similar to W. |
| 1:31.8 | Get and Curl on Linux systems. As Xavier explains in his diary from Friday, Bits offers a number |
| 1:40.3 | of features that are useful to attackers. Bits is intended to download patches, so after |
| 1:46.5 | downloading a patch you can run a script to apply the patch. Well, that's part of Bits and of course |
| 1:52.8 | often abuse to then execute the code that was just downloaded. Now Bits parser, a tool created |
| 1:59.6 | by French researchers, can be used to better understand |
| 2:03.7 | the Q manager files that are being left behind by Bits. So if Bits was used as part of an exploit, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

