meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 2nd, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 2 May 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Passive Phish Analysis; Apple Rapid Security Response; Grafana Vuln; Illumina Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, May 2, 2023 edition of the Sandtonet Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich.

0:10.2

And today I'm recording from Jacksonville, Florida.

0:15.2

Today we got a diary from Jan looking into what he calls passive analysis of obfuscated phishing emails. Typically when

0:23.6

analyzing malware, you sort of have two options. You can just do a dynamic analysis where you

0:29.2

run the malware and see what it does, which often tends to be the fast way of doing it if you

0:35.2

have a lab set up for it, but it has the risk of tipping

0:39.1

off the attacker because often you need to allow the malware to interact with the attacker's

0:44.6

infrastructure to really see what's happening. The other option, of course, is static analysis

0:50.7

where you are analyzing the source code.

0:57.7

This has the advantage of not actually running the code.

1:02.5

Of course, this case, there is no interaction with the attacker's infrastructure,

1:05.8

but tends to be tedious and slow.

1:14.6

So passive analysis is something that Jan uses specifically for JavaScript and phishing emails,

1:23.9

where what he does is he basically modifies the obfuscated JavaScript to print itself into the browser Windows by adding a document right around the JavaScript.

1:29.2

This has the advantage of basically allowing the JavaScript to decode itself and not

1:35.3

completely running the JavaScript.

1:38.0

Of course, there is still a risk that you're interacting with the attacker's infrastructure,

1:43.4

but it's kind of more a balanced method of

1:46.6

having something that's reasonably safe, but still much faster than doing the static approach.

1:56.1

And Apple today, for the first time, used its rapid security response feature.

2:01.6

This is a feature that was included in the latest iOS and macOS update.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.