ISC StormCast for Tuesday, February 7th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 February 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, February 7th, 2017 edition of the Santan and Storm Center's |
| 0:06.3 | Stormcast. My name is Johannes Ulrich, and the time recording from Jacksonville, Florida. |
| 0:12.2 | Readers often send us files and then ask, well, is this file malicious or not? We really enjoyed |
| 0:19.4 | if people send it to us, but often there isn't |
| 0:22.9 | an easy solution to figure out if something is malicious or not, in particular if it's not |
| 0:28.0 | malicious. Typically, it's relatively easy to figure out. It's ransomware or something obviously |
| 0:34.0 | malicious, but then there are a lot of border cases like spyware, ad wear |
| 0:39.4 | that may be considered malicious by some people, but not so malicious by other people. |
| 0:45.5 | And I have an interesting example here that the reader submitted earlier today. |
| 0:49.7 | That actually turns out to be pretty certainly non-malicious. It's part of a Chinese office suite |
| 0:58.2 | that apparently gets pre-installed on some HP laptops, but for example, Avast still decided to |
| 1:07.3 | label this file as possibly malicious. |
| 1:15.7 | And if you do sort of a quick automatic reverse engineering on the file, |
| 1:20.9 | it turns out that it does send data to a remote site. |
| 1:23.1 | Well, that's what a lot of office suites do. It also is able to download additional components, of course, for auto update and the like, |
| 1:29.2 | and it does have access to, for example, your browser history. |
| 1:33.7 | All of this is considered often malicious behavior, but in this case, it's also in line with |
| 1:41.0 | what an office suite typically does as it interacts with the network and with the browser. |
| 1:49.4 | I have links to some of the analysis results in the diary, so if you want to check yourself how you |
| 1:57.8 | would characterize the file, take a look. And in vulnerabilities today, we have two remote denial of service attacks against the |
| 2:05.5 | OpenBSD HTTP server. |
| 2:08.7 | A little bit disappointing here because these are well-known denial of service conditions |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

