meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, August 23rd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 23 August 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 32/64 Bit Malware; FBI Home Proxy Warning

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, August 23rd, 2022 edition of the Sands Internet Storm Center's

0:07.6

Stormcast. My name is Johannes Ulrich, and today I am yet again recording from Jacksonville, Florida.

0:17.1

In today's diary, Xavier took a look at the prevalence or lack there off of native 64-bit

0:25.0

Malver. It is almost difficult these days to find a CPU that is not 64-bit and many operating

0:32.7

systems do support 64-bit these days. But of course, Malver usually doesn't have a great reason to give up the 32-bit compatibility,

0:43.9

even if it only affects a small percentage of systems.

0:47.5

Things like performance or memory use and such, of course, is usually not a big issue for Malver.

0:53.6

Xavier's attempt to answer the question used the daily archives from Malware Basar.

1:00.8

Malware Basar, unlike a virus total, makes it easy to download large number of samples.

1:05.9

They actually have sort of a daily dump that you can download, So Xavier ended up downloading 217 gigabytes of

1:13.9

matter, which went back to February 2020, so more than two years back. And he used a

1:21.4

Yara rule to detect if a binary was either 32-bit or 64-bit. Well, the short answer, only about 6% of binaries were detected as 64-bit code, but among

1:34.9

them was only one single DLL file.

1:38.9

However, if you look at the graph that he posted, it looks like there was a steady increase

1:43.3

in the number of 64-bit samples

1:45.8

starting around the beginning of this year. So it's possible that the malware world is

1:51.3

switching to 64-bit, which of course has some implications then when it comes to detection.

1:59.0

And the use of proxies to mask an attacker's origin isn't really anything new, but the FBI issued

2:06.4

a bulletin late last week warning users that they're seeing a search in the use of proxies

2:12.6

specifically for credential stuffing attacks.

2:16.2

So credential stuffing, that refers to an attack where an attacker uses

2:20.2

usernames and passwords or other personal data that was leaked in prior breaches.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.