ISC StormCast for Monday, March 14th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 March 2022
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, March 14th, 2020 edition of the Sandsenet Storm Center's Stormcast. |
| 0:09.2 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:15.2 | Xavier on Friday came across a Malware sample that's a bit unique for its use of web sockets. |
| 0:22.6 | Usually Malware likes to use just plain old HTTP requests and various networks as well |
| 0:28.8 | as host-based security products, of course, know very well how to deal with this sort of |
| 0:34.5 | regular HTTP. Web socket, maybe a little bit of a blind spot here |
| 0:41.3 | for some of these tools in particular. |
| 0:43.3 | This sample actually doesn't even bother with TLS. |
| 0:47.3 | Only two out of the 54 anti-malrower engines |
| 0:51.3 | used by virus total are recognizing this particular sample. |
| 0:57.1 | WebSockets, well, it implements a simple two-way protocol, which is great for command control channels. |
| 1:03.6 | That's sort of how it's often used in modern web applications, but also kind of to stream data, |
| 1:09.3 | which, of course, for exfiltration may work |
| 1:13.7 | quite well. While you're playing with WebSockets, double check if your host-based data leakage |
| 1:21.2 | or data exfiltration solutions are detecting them properly. Have seen some blind spots there |
| 1:26.7 | in the past where they do |
| 1:28.3 | detect if a browser submits normal HTTP requests, but they don't necessarily detect |
| 1:34.1 | the data in web sockets. |
| 1:38.2 | And talk about command control channels, Avast found a version of Raccoon Steeler using Telegram as a command control channel. |
| 1:47.9 | Telegram is getting somewhat popular for command control due to its relatively easy to use API, |
| 1:55.9 | Raccoon Steeler. As the name implies, is an information stealer. It steals usernames and passwords, as well as |
| 2:02.2 | cookies and other authentication tokens. The data is actually not exfiltrated via telegram. However, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

