ISC StormCast for Tuesday, March 22nd, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 March 2022
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, March 22nd, 22nd, 22 edition of the Sands and the Stormsendors Stormcast. |
| 0:08.4 | My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:14.0 | Now, if you are into reverse engineering malware, you must read the DA's diary. |
| 0:20.4 | It has a pretty simple title, a maldoc cleaned |
| 0:24.4 | by antivirus, but really it turns out to be a deep dive into some of the file structures involved |
| 0:32.0 | with office documents. So the problem here was that a document was recovered that was very likely malicious, |
| 0:40.6 | but antivirus already modified and essentially removed the malicious part of the document. |
| 0:48.2 | At least that's sort of what it looked like. The antivirus in question here being Kersperski and what the DEA then attempted |
| 0:57.9 | to do is trying to recover the malicious code, which of course is interesting because he still |
| 1:02.7 | want to know what this particular piece of Malver may have done if it would have been able |
| 1:07.6 | to run. It may have, for example, run on a different workstation |
| 1:12.1 | with different antivirus that didn't catch it. |
| 1:14.9 | And then you may want to know |
| 1:17.4 | what are some of the indicators of compromise or such |
| 1:19.9 | that you should be looking for. |
| 1:22.8 | Now, the deep dive here into the document formats |
| 1:26.7 | essentially shows how Kasperski didn't actually |
| 1:29.6 | overwrite the malicious code. It just truncated the respective stream and well, by actually |
| 1:37.1 | modifying the file structures, you're able to recover and analyze that truncated stream. |
| 1:44.6 | Very interesting analysis, and like I said, |
| 1:46.6 | really the good part here is it goes into all the little details |
| 1:51.3 | of these file structures and how to manipulate them. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

