4.9 • 696 Ratings
🗓️ 10 April 2025
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, April 10th, |
0:03.2 | 2025 edition of the Sands and at Storm Center's Stormcast. |
0:08.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:13.8 | Xavier wrote about obfuscated Python. |
0:17.3 | In this particular case, the exploit first arrived as a simple script, |
0:22.6 | then use PowerShell to download additional Python. |
0:27.7 | Now, what was different about this particular Python script here is that it used Pi Armor |
0:34.3 | in order to obfuscate the code. |
0:38.0 | And, well, Xavier isn't here going towards |
0:41.2 | line by line, based on the obfuscation, |
0:44.5 | at least does show some techniques to get some |
0:48.3 | partial content from the script by doing |
0:52.9 | some behavioral analysis. The problem here again is that the script |
0:57.5 | also doesn't really run in sandboxes very well, so certainly making analysis of these scripts |
1:05.1 | more difficult. Pi armor itself is not necessarily malicious. It's often used for commercial Python scripts |
1:13.3 | in order to obfuscate the inner workings |
1:16.4 | for intellectual property protection and the like. |
1:21.1 | But if anybody has any tips here for Xavier, |
1:24.2 | how to better deal with Pi Armorour, obfuscated scripts. |
1:29.1 | Well, please let them know. |
1:30.7 | And we have an interesting vulnerability in CenterStack. |
1:34.2 | Center Stack is made by Cladinet, |
... |
Transcript will be available on the free plan in 5 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.