ISC StormCast for Tuesday, January 5th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 January 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, January 5th, 2021 edition of the Sandstone Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich Entertainment recording from Jacksonville, Florida. |
| 0:13.2 | In Diaries today, Jan did sort of well a year-in review. |
| 0:18.0 | He looked at his last year's quarantine email inbox and essentially picked a |
| 0:25.7 | random, interesting looking sample and is sort of walking us through the different obfuscation |
| 0:32.0 | techniques used in this particular sample. Turned out it started out all as an email with a well suspicious |
| 0:40.3 | attachment which was a RAR compressed file. Once decompressed well it turned into a dot |
| 0:48.3 | bad file actually had two extensions.pdf.bad probably to sort of trick the unsuspecting user into opening the file, |
| 0:57.9 | which would then, of course, launch PowerShell. And after downloading additional malware, |
| 1:05.1 | de-offuscating it, decoding it, injecting DLs, and all the other good stuff, |
| 1:10.2 | we end up with a good old info stealer. |
| 1:13.6 | So overall, a real need summary of current evasion techniques, while none of them is |
| 1:19.6 | particular sophisticated or difficult to analyze, just getting the entire sequence straightened |
| 1:26.6 | out and getting all the parts can be quite complex. |
| 1:32.3 | And Citrix released a fix for the DTS vulnerability that has recently been abused for distributed denial of service attacks. |
| 1:41.3 | So this was not really an attack against the Citrix server. Instead, |
| 1:46.9 | the Citrix server was used as an amplifier. And due to all the traffic this generated, |
| 1:51.5 | this actually sometimes then resulted in a denial of service against this Citrix server, |
| 1:58.6 | even though that was probably unintentional. |
| 2:01.7 | So DTLS is really TLS over UDP and UDP of course is easily spoofed and often abused |
| 2:08.7 | for these type of denial of service attacks, but the specification actually takes that |
| 2:15.3 | into account. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

