ISC StormCast for Tuesday, September 3rd 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 September 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, September 3rd, 2019 edition of the Sands and at Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich. |
| 0:09.5 | And today I'm recording from Brussels, Belgium. |
| 0:13.9 | Xavier came across another malware sample that actually downloads and installs a complete copy of Node.js on Windows systems it infects. |
| 0:25.6 | Notejs, of course, has become a real popular development platform for all of its libraries |
| 0:31.9 | and capabilities. It's offering in this case it's not really clear why the attacker is going through the trouble |
| 0:38.7 | to download it all. Xavier only took a cursory look at the malware, but it mostly appears |
| 0:45.4 | to implement a command and control channel. So this may not be a finished product yet, but more |
| 0:52.0 | kind of a prototype trial balloon of further malware |
| 0:56.8 | to come. Note.js, of course, is not malware by itself. It's not flagged as such by your antivirus, |
| 1:06.9 | and that may be an attempt to sort of sneak past antivirus and then just load miscellaneous |
| 1:14.4 | JavaScript snippets that of course are again also usually not detected or not even analyzed. |
| 1:22.4 | In particular, in this case, the actual attack JavaScript that's then implementing this command control channel |
| 1:30.3 | is actually arriving as a base 64 encoded comment. |
| 1:36.3 | And if you're running your own mail server in a Unix environment, it's very likely that you're using the DovCod server for IMAP. |
| 1:47.0 | Well, a remote code execution vulnerability in DovCat was just patched five days ago. |
| 1:55.0 | Certainly time to look out for updates for your Unix distribution. |
| 2:00.0 | The advisory does list a little sort of proof of concept exploit for this vulnerability, but |
| 2:06.1 | also states that actual remote code execution is quite tricky to accomplish in this particular |
| 2:14.3 | case. |
| 2:15.2 | In addition to remote code execution, this vulnerability may also be used |
| 2:20.3 | to read memory from DuffCod. DuffCod add-on Pitchin Hole is also affected, but not clear if there's |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

