ISC StormCast for Tuesday, September 6th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 September 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, September 6, 2020 edition of the Sandsenet Storm Center's |
| 0:08.0 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.2 | On Friday, D.D.E. took a look at one of the James Webb Telescope images that I mentioned last week, did he |
| 0:22.6 | used his JPEG dump Python script to help analyze them. It identified three different |
| 0:30.6 | JPEC data structures in files that embedded malware in addition to the image. |
| 0:39.8 | Now, remember, when I talked about this, |
| 0:44.7 | this is not a case where the image will execute code as you view it. |
| 0:47.6 | So the image itself is not really the exploit here. |
| 0:51.6 | It's really just used as a carrier to obfuscate, |
| 0:53.1 | if you want to call it this way, |
| 0:56.5 | or to bypass some other detection techniques, |
| 1:04.5 | and the malicious code is then being extracted by malware that the system is already infected with. |
| 1:09.7 | The JPEG dump script does allow extracting this additional data. |
| 1:28.1 | It's formatted as a certificate. Again, it isn't a certificate. The certificate is here just use it as an innocuous container for base 64 encoded data that's then being decoded into the PE executable. And Microsoft's Defender Antivirus apparently had some false positive issues over the weekend. |
| 1:34.9 | The Register and others summarized complaints from users who observed Microsoft Defender |
| 1:41.1 | flagging various applications built around the Chromium Browser Engine or the |
| 1:48.2 | Electron JavaScript framework as malicious. |
| 1:52.1 | Both of these technologies are used similarly in the sense that they do allow you to build |
| 1:58.1 | some of these native applications that really are built around |
| 2:03.2 | web applications. So it makes a web application kind of look like a native application. |
| 2:08.1 | And if you remember last week I talked about like a malicious translate application that |
| 2:13.9 | sort of use the chromium engine for example, and maybe issues like this is why Microsoft |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

