ISC StormCast for Tuesday, September 13th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 September 2022
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, September 13th, 2020 edition of the Sansonet Storm Center's Stormcast. |
| 0:09.2 | My name is Johannes Ulrich, and today I'm recording back in Jacksonville, Florida. |
| 0:16.2 | Today we've got another post by Jesse LaCrew. |
| 0:19.0 | When dealing with Malware samples from honeypots, a quick triage |
| 0:24.2 | is important. You usually have so many samples to work with. And one of the things I usually |
| 0:28.9 | recommend is, well, a check with virus total. Is it already known? That particular sample, |
| 0:34.1 | how old is it? So that's a quite useful initial triage tool. And Jesse took a |
| 0:41.3 | closer look at the results that he has been getting from Virus Total when submitting matter |
| 0:46.3 | from his honeypots. Just to summarize some of the key observations and of course there's more |
| 0:52.7 | detail in his full post. First, there are a number of vendors |
| 0:57.6 | that will not flag any of the malware caught by the honeypot as malicious. Well, not really such a big |
| 1:04.7 | problem necessarily. Some vendors are just not focusing on, for example, Linux malware. This is usually Linux malware we're |
| 1:12.4 | talking about here because it is a Raspberry Pi Honeypot. Also, it usually is being attacked |
| 1:19.1 | by most of these IoT-style malware families like Mirai. And of course, a lot of IoT vendors and such, there is no real anti-malware |
| 1:29.9 | for it. So some of the large malware vendors don't really cover these samples very well. |
| 1:36.8 | So vendor not finding these samples malicious is not necessarily a sign that this vendor's |
| 1:42.6 | anti-malware product is of lower quality. Secondly, |
| 1:47.7 | Jesse noted that the number of AV engines detecting a particular sample will increase over time. |
| 1:56.5 | Now, of course, that's not a big surprise. After all, it takes a while for different vendors to find a new |
| 2:03.0 | sample. They have, of course, in the past been some evidence of vendors just sort of blindly |
| 2:08.4 | copying signatures after a sample was found malicious on a virus total. But it was a little bit |
| 2:15.6 | surprising is that it sometimes takes weeks or months after |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

