meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 29th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 January 2024

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Batch Comments; .box TLD abuse; Jenkins CVE-2024-23897 PoC; Malicious Chinese Google Ads

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, January 29th, 2004 edition of the Sands and its Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:14.7

Xavier just doesn't get tired of finding new and interesting ways how malware is encoded.

0:27.6

The latest trick that Xavier came across is in the form of a batch files or dot BAT files, these Windows script files.

0:29.6

Well, typically they include like a script by themselves, but in this case, actually, the file just contained comments. Double colon at beginning of the line does

0:40.9

indicate a comment for a badge file. The trick here was that these comments really then included

0:48.2

or represented multiple different payloads that could be extracted from the file.

0:54.8

There was a two-digit indicator as to what particular payload was being encoded in a specific line,

1:02.9

and then a line number.

1:05.3

Now, the line numbers weren't initially sorted, but based on using the line number,

1:10.1

then a PowerShell script or a simple

1:13.0

bash script or whatever can be used to then extract a specific script, decoded, and then

1:21.7

executed.

1:23.1

Sagan took a closer look at the Malver that was extracted from this particular batch file.

1:28.5

It was a connection to a command control channel that used port 443 but was not encrypted with

1:37.3

TLS. So just some simple sort of command control protocol, lots of pinks and pongs, which is kind of typical

1:45.3

to just establish that connection succeeded.

1:49.6

Antivirus total score was pretty low with only one out of 60 antivirus tools identifying

1:55.7

this sample as malicious.

1:59.6

Now we got an interesting issue for users of the routers from Fritzbox.

2:05.8

They're particular popular in the German-speaking parts of Europe.

2:10.8

And I'll link to an article that describes the problems here that is in German,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.