ISC StormCast for Thursday, October 10th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 October 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, October 10th, 2019 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.6 | My name is Johannes Ulrich, and I'm recording from Chicago, Illinois. |
| 0:13.8 | Brad in his diary today is talking about the VIDAR information stealer, and in this case case he is looking specifically at the data that |
| 0:24.3 | this information stealer does exfilterate. |
| 0:28.1 | Now of particular interest is a post request that is sending a SIP file to the command |
| 0:35.7 | and control server. |
| 0:37.4 | Now this post request is not just sending the SIP file. |
| 0:40.3 | It's actually a multi-part mime encoded post. It's sending a couple of additional piece information, |
| 0:47.3 | like for example, a hardware ID, the exact operating system, architecture and the like. So if you are using just the plain |
| 0:57.7 | Wyrshark export objects feature and export the HTTP object, what you end up |
| 1:03.9 | with is not just the SIP file, you're ending up with the entire multi-part mime request. |
| 1:11.0 | So what you'll have to do here is you will have to remove the respective header, everything |
| 1:18.0 | up to the PK header of the particular zip file, and that leaves you then with just |
| 1:25.7 | the zip file. |
| 1:27.3 | As usual, Brad has a step-by-step walkthrough of this particular process, so it shouldn't |
| 1:33.7 | really be that hard to replicate it for you. |
| 1:37.1 | And of course, you also get links to the actual P-CAPs, so you can experiment with this. The zip file, well, no huge surprises here, things like screenshots, passwords and other information |
| 1:51.0 | are being exfiltrated by this information stealer. |
| 1:55.0 | And if you got details regarding two of the vulnerabilities that Microsoft patched this week |
| 2:02.8 | as part of the Big Patch Tuesday. |
| 2:06.5 | The two vulnerabilities CVE 2019, 1166 and 1338 are somewhat similar in that they do affect the message integrity check or |
| 2:20.3 | make in NTLM authentication. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

