ISC StormCast for Monday, March 6th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 March 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, March 6th, 2017 edition of the Sandsenet Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.4 | Xavier looked at some recent malware and found that the malware doesn't use standard image hosting sites to load its images from |
| 0:23.3 | at least for one of the images. |
| 0:26.9 | It was using an unsuspecting third-party site that just happened to have the right progress |
| 0:33.8 | bar image that this particular malware author liked. This can have some bad repercussions |
| 0:40.7 | for the site hosting the image as it may show up now in various threat intelligence reports |
| 0:48.1 | as an indicator of compromise leading back to the site being blocked. |
| 0:55.0 | Really unfortunate if this happens to you and not terribly much you can do about it, you can prevent some of this deep linking by looking for referrher headers and blocking any foreign |
| 1:08.0 | referr headers from your site. But again, remember, referrer headers aren't always |
| 1:13.3 | sent, so you have to at least allow for requests that don't send a referer at all. And if you would |
| 1:22.0 | like to learn more about analyzing malware, in particular de-obsuscation, DDA put together a nice example of an obfuscated malicious document. |
| 1:32.3 | In this case, additional characters were used to pad and obfuscate the malicious code. |
| 1:38.3 | The DA will show you how to remove the padding characters and how to reverse the embedded PowerShell script |
| 1:46.0 | in this particular case. |
| 1:47.0 | Also interesting but not really new that the script does take advantage of the event viewer |
| 1:53.5 | exploit to bypass UAC. |
| 1:57.0 | And as a reminder, it's not just Adobe's PDF reader that is vulnerable. |
| 2:02.9 | Fox IT has a patch for its fandom PDF and PDF reader product. |
| 2:09.4 | So in case you use these products to evade Adobe exploits, make sure you patch it soon. |
| 2:16.2 | They have certainly been exploited in particular against the |
| 2:19.5 | Fox ID PDF reader in the past. And Google's SHA-1 collision has been put to use to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

