4.9 • 696 Ratings
🗓️ 9 September 2018
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, September 10th, 2018 edition of the Sandton and Storm Center's |
0:06.1 | Stormcast. My name is Johannes Ulrich. And the time recording from Amsterdam, Netherlands. |
0:14.1 | And just when you think there isn't really much new to talk about when it comes to crypto coin mining, |
0:19.7 | Xavier came across some interesting matter |
0:23.6 | that ran crypto coin mining in a browser in headless mode. Headless mode refers to running a |
0:30.6 | browser without GUI. Now typically that's done in order to provide access to the browser |
0:36.6 | from scripts. |
0:38.7 | In this case, the script, of course, is malicious and is then used to load JavaScript |
0:45.3 | into Chrome, which here is run without its GUI, so the user doesn't even know that Chrome |
0:52.2 | is running at all. |
0:53.7 | A second interesting trick, but by far from new, that the malware is using, |
0:59.0 | is to actually use Rec Server 32 in order to launch the malicious code. |
1:06.0 | This way it does bypass most whitelisting techniques. And of course the difference between using a tool like, for example, W. Get curl or Bits admin |
1:16.6 | instead of running the full browser in headless mode is that the browser does parse JavaScript |
1:23.6 | while these other command line tools usually just retrieve the code but don't run it. |
1:30.3 | And also running JavaScript in a browser is less likely to trigger any anti-malver or |
1:36.3 | whitelisting systems. |
1:38.3 | Now for the coin hive code itself, of course, yes, that particular code has been added to many anti-malware tools. |
1:47.0 | And talking about anti-malware, or in this case, better anti-adware, on Friday, Twitter user |
1:56.0 | privacy is first noted that anti-adware application adware doctor, which is sold in the Apple App Store, |
2:04.7 | has been exfiltrating browser histories and apparently has been doing so for quite a while. |
2:12.1 | Now, the Apple App Store does impose some restrictions for MacOS and OS 10 applications by most notably |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.