4.9 • 696 Ratings
🗓️ 30 March 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, March 30th, 2020, |
0:04.5 | edition of the Sansonet Storm Sturmast. |
0:08.6 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:14.5 | One thing we love is if you send us Malware that you have issues reverse analyzing, and we had a reader Martin send us malware that you have issues reverse analyzing and we had a reader martin sent us such a sample |
0:25.5 | earlier today and did he took a look at it and found that well it was an excel spreadsheet and it did |
0:34.6 | have malicious content but that malicious content was spread over multiple streams. |
0:40.9 | So DDA is going over how to extract the relevant streams by using the JSON output format of his |
0:48.2 | tools and then how to extract respective streams from the file. |
0:59.0 | And to accomplish that, DDA also on the fly made a quick update to one of his tools that allows you to easily save these multiple streams in just one command. |
1:05.8 | More details about all the different Python tools that DDA used from his arsenal |
1:10.4 | can be found in the diary from |
1:14.1 | Wednesday. |
1:16.6 | Well, and bad news for you if you're using the 3CX voice over IP solution, the 3CX desktop app, |
1:24.5 | which is their voice over IP phone, apparently got compromised and includes malicious code. |
1:31.5 | At this point, multiple antivirus |
1:33.6 | solutions are flagging the compromised |
1:36.1 | binary. As part of this |
1:39.2 | binary attackers will be able |
1:41.2 | to execute arbitrary commands on |
1:44.0 | systems running the affected version of the |
1:47.5 | 3CX desktop app. |
1:50.3 | Both Windows and Mac versions of the application are affected. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.