4.9 • 696 Ratings
🗓️ 4 June 2020
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, June 4th, 2020 edition of the Sandcent Storm Center's Stormcast. |
0:06.8 | My name is Johannes Orrich, and today I'm recording from Jacksonville, Florida. |
0:12.3 | In today's diary, Brad is looking at a recent copy of the sea loader malware. |
0:18.9 | It was actually peddled using Polish language malicious spam messages. |
0:26.1 | Now, overall, nothing really all too special here. It's an Excel spreadsheet with a macro |
0:31.5 | that will then download the C-loader.dll.L. One thing of note here is that all the traffic is HTPS. So if you |
0:41.7 | don't inspect HPS traffic, you're pretty blind here. On the other hand, once you do inspect |
0:50.0 | HTTP, there are a couple sort of telltale signs here like odd user agent headers and the like that should make it pretty straightforward to actually detect this kind of malware. |
1:03.0 | If you don't have TLS inspection, you are pretty much left with DNS lockups. |
1:09.4 | And there are some sort of interesting host names here. Not sure how |
1:14.8 | well they would sort of pop up in a busy network. They are using the dot AT top level domain. |
1:22.6 | I believe that's Austria that does use .AT. |
1:30.5 | So not a super common top level domain, |
1:36.1 | but nothing like the dot XYC or dot top top level domains that are calmly used by malware. |
1:39.6 | Another giveaway here, of course, |
1:40.9 | is also that the binary is directly downloaded, |
1:44.0 | so you'll get your |
1:45.5 | typical Windows executable header. That's also pretty easy to pick up on for any kind of |
1:52.3 | intrusion detection system. And Cisco fixed an interesting flaw in a number of its |
1:59.8 | routers and switches affecting the IP in IP protocol. |
2:04.6 | It's a little bit of weird protocol where we are really just sending an IP packet inside another IP packet. |
2:11.6 | So you have two IP headers following each other, almost a little bit like a shortcut to GRE, which you could |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.