meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, June 28th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 28 June 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Malware Triage; RowPress Attack; Dell BIOS Update;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, June 28, 2003 edition of the Sanchez Storm Center's Stormcast.

0:08.6

My name is Johannes Ulrich and I'm recording from Stockholm, Germany.

0:14.2

Xavier today wrote a diary, lifting a little bit of the curtain about how matter analysis is done sort of at scale. And the key here is really triage,

0:24.8

basically finding the samples that are worthwhile to analyze further. So the two methods that

0:32.1

Xavi is introducing here is one, a quick sort of tool chain to extract malicious files or files, period, from emails,

0:40.8

then running them through, for example, some Yara rules and such to find interesting things.

0:46.4

Secondly, a tool that I actually wasn't familiar with, and Xavier said he learned about this

0:51.9

from Jim Glossing, another handler of us.

0:55.9

And that tool is called QuickScope.

0:58.1

QuickScope, typically runs in a Docker container.

1:01.1

And one of the big advantages is that, first of all, it's customizable, but it also can deal with a wide range of different files, executables for different operating systems, even like APK files

1:13.7

and such, unpack them and then run some basic static analysis against them in order, again,

1:20.5

to do some simple signature matching and essentially figure out what's worthwhile analyzing further. My sort of quick take on some of the triage is also that one thing that I like to do is

1:33.3

if it's just a random sample that I received in an email and it does already trigger signatures

1:40.3

in common anti-malware tools, then typically it's less interesting to do sort of a

1:46.7

complete analysis on it. Of course, this may also depend a little bit on the context if the sample

1:52.4

was involved in an actual compromise or if this is just something that you received in an email

1:58.5

but are pretty certain that it hasn't actually been

2:01.9

executed yet.

2:04.1

And then we got yet another variety of the Rohhammer attack.

2:08.1

This one comes from researchers at ETH Surich.

2:12.4

And the problem here is, well, actually, let's first talk a bit about Rohammer. Rohammer means that

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.