
ISC StormCast for Wednesday, August 31st, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
The Sands and Its Storm Centers - A Brief Review
The entire command control channel is implemented as a simple bash script. The script does not just launch a command line or sek lined. Instead, it uses the df t c p trick in order to get access to the i r s server. Not sure why they didn't go for a better hash, given that the code really wouldn't be all that different.
Transcript
Play full episode