meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 27th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 27 February 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VirusTotal API and Honeypots; WPA2 Auth Bypass; Subdomain Spam;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, February 27th, 2024 edition of the Sandcent Storm Center's

0:08.0

Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:15.2

In today's diary, we do have a guest diary by Kegan Hamlin, one of our interns, and Kegan is writing about

0:25.1

how to automate some of the malware analysis with our honeypot.

0:30.6

We are using the Cowry Honeypot, and it does collect any attempts to upload binaries or any file, really, to the Honeypot and it does collect any attempts to upload binaries or any file really to the Honeypot.

0:41.8

And of course, there is malware among those binaries.

0:46.0

The tricky part is to serve a quick triage on what's interesting, what's new.

0:51.9

Virus Totals API comes in really handy here. You may just use it to

0:57.4

submit a hash of the file and then you'll get back some basic properties that VirusTotal

1:05.5

knows about the file. As a rule of them, well, if VirusTotal has a record of the particular

1:10.7

hash, it's probably

1:12.2

not that terribly interesting, even less interesting if there are a lot of hits in existing

1:18.9

anti-malreras engines. Now, once you make it past this step, there's some interesting

1:24.7

additional step that is being explained here, and that's the

1:29.8

behavioral or dynamic analysis of the files, and here using any run. Any run is a service that you can

1:38.2

use to then quickly, basically run a file and get a quick report as to what it does. Works pretty well,

1:46.8

and then in addition to that, you have tools that you can sort of deploy yourself, like

1:51.9

a Mockenbird or Kuku3, which are also allowing you to get a quick behavioral snapshot of some unknown matter.

2:03.1

Some of these sort of on-premise systems, of course, take a little bit work to get set up

2:08.5

and configure.

2:09.9

They often require a set of different virtual machines and the necessary automation

2:15.8

to then periodically reset everything. Again, this is

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.