ISC StormCast for Wednesday, August 26th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 August 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, August 26, 2020 edition of the Sandcentred Storm Center's Stormcast. My name is Johannes Ulrich. I'm recording from Jacksonville, Florida. |
| 0:13.4 | Quick diary today from Xavier about Living Off the Land Bineries or Lowell Bins. It really has gotten a lot of attention in the last couple years. |
| 0:22.5 | And what is all about is attackers not just uploading matter to your system, but instead |
| 0:29.6 | using software that's already installed on the system to do a lot of things that, well, |
| 0:35.9 | they in the past used malicious software for that was easily |
| 0:40.3 | detected. |
| 0:41.3 | Now this is a topic that we have covered before and some of these binaries like for example |
| 0:48.8 | Bits admin or cert util are heavily abused but not so often used really by normal users. So that's what this |
| 0:59.1 | approach to detecting misuse of these binaries is all about, that you're using tools like |
| 1:05.6 | Sysmon and PowerShell to figure out who and how these particular binaries are used. |
| 1:14.7 | Now, in general, we don't really talk a lot about iOS malware, because Apple, with its very |
| 1:20.0 | restrictive App Store, has been pretty good in keeping Malware out of the iOS ecosystem, but ever so often someone sneaks past it. |
| 1:32.1 | And, well, just appropriately that sneak the company that detects vulnerabilities, |
| 1:39.2 | independencies, libraries and such, discovered this ad network SDK by MoVista, a Chinese mobile ad tech company |
| 1:50.1 | that does misbehave and does steal ad revenue. |
| 1:55.2 | Now yes, this particular software development kit, if used by a developer in order to integrate ads |
| 2:01.6 | into the application, does exfiltrate more user information than it really should. |
| 2:09.6 | But the actual victim here is as much the developer that integrated the ad network, as well as other ad networks, |
| 2:18.2 | in that it claims clicks to come from its ads, |
| 2:22.7 | even though another ad networks, |
| 2:25.3 | SDK may be used to display a particular ad, |
| 2:28.5 | but it also may just generate fake clicks, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

