meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, May 1st 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 1 May 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Simple Obfuscation Bypasses AV; OS X Proxy Malware;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, May 1st, 2017 edition of the Sansanet Storm Center's Stormcast. My name is Johannes Ulrich,

0:08.5

and I'm recording from Jacksonville, Florida. One thing we always enjoy is if people send us Malware and Xavier looked at

0:17.6

one sample on Friday. It used a pretty sort of interesting obfuscation technique,

0:24.1

which led to only five antivirus tools actually recognizing this particular sample as malicious,

0:31.7

even though it was, well, just another vert macro. So first little trick that this malware plays is that it doesn't actually start automatically.

0:40.6

The user has to first start the macro.

0:44.5

This removes one common signature that's being used and this is the auto open function.

0:51.3

Secondly, the malware then downloads additional code and that's again kind of common,

0:57.5

but it does so iteratively. So each download does give it another snippet of code. Essentially,

1:04.6

it checks just what works. That code itself is heavily obfuscated and then exhort with a key that was downloaded in the initial

1:14.3

matter. So without the auto-open function and no recognizable executable being transmitted across

1:23.2

the network, that apparently does cause problems for many antivirus products in this particular

1:30.9

case. However, no need to be too concerned about this particular sample because in the end it

1:37.2

actually ends up downloading fairly commodity malware that is widely recognized. We have seen this

1:43.3

before where attackers go through quite a few hoops

1:47.3

and use fairly sophisticated exploits initially, but then end up downloading commodity malware

1:53.6

that doesn't really work if you have any kind of reasonable antivirus installed. However,

2:00.5

I wouldn't totally discard the sample.

2:03.5

Another thing that often happens, if the first sample is being downloaded is being caught

2:08.7

by antivirus, you may actually see the downloader reach out to additional URLs and then

2:15.2

download additional malware until it finds a sample that does not

2:20.0

get recognized by your antivirus.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.