4.9 • 696 Ratings
🗓️ 14 November 2016
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, November 14th, 2016 edition of the Sands and the Storms and a Stormcast. |
0:08.1 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
0:13.0 | Last week, the DA was writing about malware that was using a process replacement technique |
0:19.9 | in order to hide itself from whitelisting protection. |
0:24.6 | Well, one of the questions that came up from readers was whether or not EMIT will actually prevent |
0:30.6 | this malware from working. And turns out, indeed, in its default configuration, EMIT will |
0:37.0 | prevent this from working if you have the |
0:39.7 | export address table access filtering or short EAF enabled and that's enabled by |
0:46.5 | default for word that will block this exploit technique and just terminate the |
0:52.7 | word process without having the final part of the |
0:56.5 | exploit execute. |
0:58.0 | Of course the visual basic script will still run. |
1:02.0 | It just can't pull off this process switching trick in the end. |
1:07.5 | And with all the attention spent to Mira and its variants, it's easy to forget, there's |
1:13.6 | still other stuff happening as well. Ghee is seeing lately a lot of Bitcoin miners being |
1:19.6 | uploaded to weekly configured FTP servers. He's using Honeypot to collect samples. You have seen Bitcoin miners and of course |
1:29.7 | yes Bitcoin is still a thing and Bitcoin mining can still make you some money |
1:34.3 | in particular if you're using someone else's computer. You typically notice that a |
1:40.1 | Bitcoin miner is running on a system just based on the system running slower overall |
1:46.0 | and pecking out its CPU load. |
1:49.0 | Now, proactively, what you may want to do is just scan your environment for FTP servers |
1:55.0 | and then of course check for weak passwords. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.