ISC StormCast for Monday, October 2nd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 October 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, October 2, 2017 edition of the Sanchez, Storm Center's Stormcast. My name is Johannes Orich, and I'm recording from Jacksonville, Florida. |
| 0:12.7 | Last week, we reported about Showtime being used in order to host Clineside JavaScript that would mine crypto coins. |
| 0:22.9 | The script in particular was created by Coin Hive, and I wouldn't characterize the script |
| 0:29.6 | as malicious, but more the use of the script without informing the user. |
| 0:36.3 | Now, I do think that video sites are so attractive to these scripts, |
| 0:41.0 | because of course the script will run the entire time that you are viewing the video. |
| 0:46.9 | The latest instance comes courtesy of Dave Holzer. |
| 0:50.8 | He found the script on Onitube.com, in part because it took so much resources |
| 0:57.4 | from his system that actually on his Mac, it alerted him that Safari took an exorbitant |
| 1:04.1 | amount of power. On video sites, of course, this may cause also problems with the playback quality if your |
| 1:12.6 | CPU is busy mining crypto coins and doesn't have any cycles left over in order to decode |
| 1:20.6 | video. |
| 1:21.6 | Now, this recent script from this weekend was heavily obfuscated. |
| 1:26.6 | The Showtime script, at least the samples that I have |
| 1:29.6 | seen mentioned from Showtime, were not obfuscated, so there was a little bit easier to spot |
| 1:35.9 | that it was actually a Coin Hive script. Now, one thing I noticed with Onitube was that they also |
| 1:42.7 | had some suspect advertisements for |
| 1:46.0 | flash player updates when I visited with my Mac, so probably not a high reputation site in the |
| 1:55.0 | first place. |
| 1:56.0 | At OS10 for a while now has marked downloaded files as suspicious and warned users whenever they |
| 2:05.8 | executed them. |
| 2:07.1 | That included JavaScript files and the user usually gets a pop-up box telling them that this |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

