ISC StormCast for Thursday, April 9th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 April 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, April 9th, 2020 edition of the Sandtonet Storms, |
| 0:06.0 | Stomast. |
| 0:07.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.0 | Brad today looked at another copy of the C-loader malware. |
| 0:18.0 | What was sort of a little bit interesting here that the actual email that tricked the user |
| 0:22.9 | into opening the file was written in German and, well, came from an Australian from address. |
| 0:30.2 | Now, the attachment was a SIP file that then unciped into a VBS file. |
| 0:37.8 | So very typical pattern here that we have seen many, many times before. |
| 0:43.0 | And then what's also more and more common that the follow-on traffic, |
| 0:47.0 | where the loader actually downloads, |
| 0:49.5 | the malware is all HTTP. |
| 0:52.7 | Brad is discussing how to deal with that. |
| 0:55.4 | In this particular case, he essentially just set up a man in the middle to retrieve keys |
| 1:01.7 | to then decrypt the traffic. |
| 1:03.8 | And as usual, Brad is making a sanitized copy of the P-Cap and the decryption keys available. |
| 1:12.5 | So you can actually go through the procedure to decrypt the traffic. This is very similar to collecting the |
| 1:20.2 | pre-master secrets from the browser. You may have done that. That's not that hard, for example, |
| 1:26.5 | in Chrome. But here, the endpoint, of course, |
| 1:31.0 | was the proxy, so the premaster secrets had to be retrieved from the proxy in order to then |
| 1:37.7 | decrypt the packet capture. It's a real nice exercise here to sharpen your pack analysis skills to follow Brad's work here. |
| 1:48.0 | And like I said, all the P-Caps are available, all the key files are available, and he walks you step by step through the process of actually analyzing the traffic. |
| 1:58.5 | Great refresher, of course, if you ever took the SEC 503 intrusion |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

