ISC StormCast for Monday, November 7th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 November 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, November 7, 22, |
| 0:05.6 | edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich, |
| 0:10.8 | and I'm recording from Jacksonville, Florida. |
| 0:15.0 | Got a couple interesting diaries from this weekend to talk about, first one by Xavier, |
| 0:19.8 | about a new version of these new to |
| 0:22.6 | Xavier of Remco's downloader. |
| 0:25.9 | This is one of those cases where the downloader has real low virus total recognition, while |
| 0:32.5 | the DLL file it's downloading has high recognition. |
| 0:36.8 | You may now say, hey, you know, what's the point? |
| 0:39.0 | The important, the dangerous part is the DLL. |
| 0:42.2 | That's kind of true. |
| 0:43.3 | But with the downloader having such a low recognition, that of course means that |
| 0:48.5 | an attacker just has to swap out the DLL and can then still use the existing downloader that may be initially |
| 0:57.3 | installed on your system. |
| 0:59.9 | What may make this particular downloader so hard to detect is in part the use of Unicode and |
| 1:07.1 | of course a lot of tools have issues with dealing properly with Unicode. |
| 1:12.6 | That's probably something that's going to show up more and more as more and more programming |
| 1:18.2 | languages also support Unicode for the actual code. |
| 1:23.4 | So that requires that the tools analyzing the code will properly analyze and be able to figure out Unicode characters. |
| 1:35.0 | And talking about relatively simple tricks to obfuscate your malware and make it difficult for anti-malware tools to detect. |
| 1:43.4 | Guy ran into a malicious executable. |
| 1:47.4 | It actually arrived as a .vhd file. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

