ISC StormCast for Thursday, June 10th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 June 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, June 10th, 2021 edition of the Sands and at Storms anders Stormcast. |
| 0:08.0 | My name is Johannes Ulrich. |
| 0:09.7 | And today I'm recording from Jacksonville, Florida. |
| 0:13.8 | Jan in today's diary looked again at different simple evasion techniques for malware. |
| 0:20.5 | In the last diary he wrote, he compared 64-bit and 32-bit software and how differently it was |
| 0:28.5 | detected. |
| 0:29.5 | Now he looked at two different compilers, the TDM GCC compiler as well as Microsoft's own |
| 0:37.1 | compiler. Now he compiled three different files, a benign file, |
| 0:42.5 | the ACAR file, which of course just a standard pattern that should always be detected. And then, |
| 0:48.3 | of course, interpreter as sort of very common and not all that difficult to detect a piece of malicious code. |
| 0:56.9 | Turned out that actually Metterpreter was detected far more often than the ACAR pattern. |
| 1:02.4 | That sort of surprised me a little bit, but yes, it certainly depends on what compiler you're |
| 1:08.3 | using in the first test TDMGZ compiled binaries were detected much more |
| 1:15.5 | frequently usually than Visual C. But the two compilers were somewhat close and making some changes |
| 1:23.7 | to the code can easily sort of flip that balance or make it more similar. |
| 1:30.4 | The root of this particular behavior is likely that different compilers are optimizing |
| 1:35.3 | code differently. So if you're starting out with the same source code, you may end up with |
| 1:41.0 | different binaries. And of course, the antivirus tools, they will include signatures for very specific binaries |
| 1:49.6 | compiled with very specific compilers. |
| 1:53.1 | And then hacker by just changing some optimization settings or using a little bit an odd |
| 1:58.4 | compiler may be able to evade many of these signatures. |
| 2:04.1 | And then we got yet another interesting attack |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

