SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) cover image

ISC StormCast for Friday, September 23rd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

00:00

Script to Install Remcos Rat

Savier to day wrote about a trick that he saw being used to install remcos rat, a common remote access tool. The attacker added a bite order mark, f f f e as the first two bites, which causes the file to be displayed as u t f 16 in editus and the like. But if you're just executing the file, the bide order mark is ignored, and well, the file is just interpreted as asky or u t f eight,. And that way descript then runs just fine.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app