ISC StormCast for Wednesday, May 19th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 May 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 19th, 2021 edition of the Sandson and Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich. |
| 0:09.6 | And then I'm recording from Jacksonville, Florida. |
| 0:13.6 | Xavier came across an interesting malware sample that actually manages to execute JavaScript on a Windows system. |
| 0:23.1 | This is accomplished using Run DLL 32, |
| 0:27.8 | a technique that has been around for a while, |
| 0:30.4 | but is not commonly used in Malware so easily overlooked, |
| 0:35.4 | and it's one of these living off the land techniques where |
| 0:39.8 | the attacker uploads a piece of JavaScript and then uses tools like RunDL32.EXC to execute |
| 0:48.7 | it. |
| 0:49.5 | The reason that RunDL32 exists is that it's able to load DLL files and then execute certain functions |
| 0:59.1 | of these DLL files. |
| 1:01.1 | That's exactly what happens here. |
| 1:03.7 | The command line parameters are first JavaScript colon, then link to the library, and then finally the little bit of JavaScript that the attacker is |
| 1:14.9 | attempting to execute. In the end, the attacker then of course pivots to PowerShell where most |
| 1:22.1 | of the exploit happens. For more details, take a look at Xavier's diary entry. An ESET published a report outlining |
| 1:32.7 | some vulnerabilities that ESAT found in Stalkerware for Android. Stalkerware usually refers to |
| 1:42.0 | software that can be used to track a victim. And this distinguishes itself |
| 1:47.6 | by being rather stealthy about what it does. So it's not easy for the victim to figure out that |
| 1:54.3 | the victim is actually here targeted with this particular software. What he said found was that starting in early 2019, |
| 2:04.3 | they saw a big increase in that kind of matter. |
| 2:09.3 | But in their work that they published this week, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

