ISC StormCast for Monday, March 20th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 March 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, March 20th, |
| 0:02.7 | 2017 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:12.1 | Xavier talked about an interesting malware sample on Saturday. |
| 0:16.6 | In this particular sample, the downloader actually acts in a number of stages. |
| 0:22.6 | And one interesting part here was that part of the initial download was a bitmap file that |
| 0:29.3 | turned out to be an obfuscated executable. |
| 0:33.2 | Bitmap files, of course, are usually not inspected by anti-malware, so by loading a bitmap onto the system |
| 0:41.3 | and then have a fairly benign little script that will decrypt it and turn it into an executable, |
| 0:47.3 | you may be able to bypass some anti-malware systems. |
| 0:52.3 | And even if it won't work on the endpoint itself, it most |
| 0:57.2 | certainly will evade detection on gateways like proxies and the like that are inspecting |
| 1:03.6 | code at rest. Another not really new lesson but sort of reinforced by the sample |
| 1:09.9 | when it comes to anti-malware is that much |
| 1:13.6 | malware is loading multiple pieces off code onto a system and then essentially just hoping that |
| 1:20.6 | one of them will not get disrupted by anti-malware so whenever you see the warning that your anti-malware program has found something |
| 1:30.5 | malicious on your system and it turns out to be a real malicious sample, you always have to |
| 1:35.7 | worry about what else was loaded on the system that your anti-malware has not picked up. |
| 1:41.7 | I've seen cases where anti-malware sort of picked up literally |
| 1:45.8 | dozens of malicious pieces of code, but eventually one malicious piece that's not being detected |
| 1:53.6 | makes it onto the system and then of course causes damage. All of this can be caused by the same |
| 2:00.6 | downloader. An interesting paper by researchers at the |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

