meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, May 22nd, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 22 May 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. HTA Analysis; Encoding Mistakes; PyPi Attack; PyPi PGP Signatures; npm RATs

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, May 22nd, 2003 edition of the Sandcent Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.4

We got a couple interesting diaries from this weekend to talk about.

0:17.1

First, a third part to DDA's analysis of an HTA file.

0:23.3

Last episode, DDA ended up with a bad file that now is being analyzed further.

0:31.3

This bad file turned out to be heavily base 64 encoded.

0:36.0

So DTDA had to work past that and shows a couple tricks how to improve the decoding here

0:42.3

until, well, he finally ends up with a PowerShell script and from there with some dotnet code as well.

0:50.1

So as usual with Didier's Diaries, great material for any reverse analysis person here to

0:57.6

walk through it and hopefully learn from it. So with it hackers using all these different encodings,

1:05.6

the question of course is how do attackers get it right? After all, as you can see in DDA's diary,

1:12.8

it's not always easy to decode all of these different encoding types.

1:17.7

Well, the answer comes from Xavier in an earlier diary.

1:22.8

Xavier has an example where the attacker actually didn't get the encoding right.

1:28.0

It looks sort of like a UTF8 versus UTF16 confusion here. When you look at the email, you're seeing what

1:34.5

appears to be sort of Chinese characters, but while it's just badly encoded, which is why

1:41.3

Outlook doesn't properly display the email.

1:45.4

So luckily nothing to worry about.

1:47.0

Of course, attackers will eventually fix the encoding issue,

1:50.2

and the email may give you a little heads up as to what email to expect next.

1:57.6

And more problems for Pi Pi, the Python module registry.

2:02.6

Apparently, they are now getting so many malicious registrations for new accounts and new projects

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.