# Community Review - February 23, 2024

**URL:** <https://community.emergingthreats.net/t/community-review-february-23-2024/1547>\
**Category:** Announcements\
**Created:** [February 23, 2024, 6:00am UTC](https://community.emergingthreats.net/t/community-review-february-23-2024/1547 "2024-02-23T06:00:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [February 23, 2024, 6:00am UTC](https://community.emergingthreats.net/t/community-review-february-23-2024/1547/1 "2024-02-23T06:00:00Z")

</div>

Greetings all, we’re back with another community update! The Emerging Threats Open ruleset is researched, written, tested, and released by the ET team based on public disclosures, writeups, and kind tags and shares by our community. Lets look at a few!

Lets start with this from @[rivitna2](https://twitter.com/rivitna2), SID 2050809 alerts on #Synapse #Ransomware infection checkin - the content in the body of the HTTP request for the outbound POST from the tweet made it happen!

> <https://twitter.com/rivitna2/status/1757053934852583891>

From @[malwrhunterteam’s](https://twitter.com/malwrhunterteam) identified hash allowed us to analyze the detonation and write a TLS SNI signature on the session connection observed - that’s SID 2050805:

> <https://twitter.com/malwrhunterteam/status/1757157145160593875>

Friend @[viriback](https://twitter.com/viriback) shared to our community #discord (DM for an invite!) a Hatching sandbox run for #MalwareAsAService #BunnyLoader 3.0 traffic - analysis rendered out so much activity to sig, including the check-in (2050885), response (2050886), client heartbeat out (2050887), heartbeat response (2050888), client tasking checkin (2050889), response from the controller (2050890), and other traffic allowing for comprehensive coverage!

> <https://twitter.com/ViriBack/status/1757953408747569644>

Here’s @[suyogi41](https://twitter.com/suyogi41) sharing #ElusiveStealer and another case of using #telegram to C2 - SID 2051071 alerts on that outbound traffic keying on an identified content byte pattern:

> <https://twitter.com/suyog41/status/1760168286711677328>

It’s an #exploit world out there with seemingly a new CVE or disclosure every day. Here at ET we do our best to provide coverage for your information assets - this comes from analyzing writeups, PoCs, and doing our own internal testing and honeypot analysis in order to best deliver for our customers and the community.

We released multiple signatures to cover different scenarios for #CVE\_2024\_1708 & #CVE\_2024\_1709 for #ConnectWise #ScreenConnect. Simply by adding a `/` to the end of the setupwizard URI it can be invoked even if it has already been completed–allowing for creation of a new admin account. SID 2050988 covers those attempts and 2050989 a successful exploitation. SID 2050990 identifies vulnerable versions of ConnectWise within your monitored environment, and 2050991-2050992 an attempt and success of a user creation action via SetupWizard via this auth bypass.

Here at our skilled #Discourse community at [https://community.emergingthreats.net/](https://community.emergingthreats.net/) - we answer questions, provide some rule writing tips, maintain a FAQ, and intake rule suggestions from all our contributors. Here, @Jane0sint provides on #MeduzaStealer - check out their process for what became SIDs 2050806 and 2050807!

> [@Medusa Stealer](https://community.emergingthreats.net/t/medusa-stealer/672/6):
>
> Hi I want to suggest one more Signature alert tcp any any -\> any any (msg: "ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M2";flow: established, to\_server;stream\_size: server, =, 1;content: "ewogICAgIkdyYWJiZXIiOiBbCiAg"; depth: 28; classtype: credential-theft;classtype: trojan-activity; reference: md5,d1c95dfd50744b0133abd72801b8a0f3; reference: url,community.emergingthreats.net/t/medusa-stealer; metadata: attack\_target Client\_Endpoint, deployment Perimeter, former\_category MALWARE, signa…

User @kevross33 provides two #TinyTurlaNG #APT signatures - an outbound beacon (SID 2050902) and a client task ask (SID 2050903):

> [@SIGS: ET TROJAN TinyTurlaNG Turla APT](https://community.emergingthreats.net/t/sigs-et-trojan-tinyturlang-turla-apt/1382/3):
>
> 2050902 - ET MALWARE TinyTurlaNG Turla APT Initial Client Beacon 2050903 - ET MALWARE TinyTurlaNG Turla APT GetTask Request

More than a few SIDs from industry contributers lately as well! The shared research within these blogs and media releases allows us to carefully analyze and identify the precious intel (in the form of HTTP content patterns) within so we can write performant sigs for #etopen. Here, @[bitdefender’s](https://twitter.com/bitdefender) blog on #MacOS #RustDoor gave two alerts for outbound activity (2050799-2050800) life!

[www.bitdefender.com/blog/labs/new-macos-backdoor-written-in-rust-shows-possible-link-with-windows-ransomware-group/](http://www.bitdefender.com/blog/labs/new-macos-backdoor-written-in-rust-shows-possible-link-with-windows-ransomware-group/)

This @[rapid7](https://twitter.com/rapid7) blog inspired SID 2050811 which detects attempts to exploit a command injection vulnerability in some QNAP devices in the quick.cgi script using the “uploaf\_firmware\_image” function:

> **[CVE-2023-47218: QNAP QTS and QuTS Hero Unauthenticated Command Injection...](https://www.rapid7.com/blog/post/2024/02/13/cve-2023-47218-qnap-qts-and-quts-hero-unauthenticated-command-injection-fixed/)**
>
> Rapid7 Labs has identified an unauthenticated command injection vulnerability in the QNAP operating system known as QTS.

More #TinyTurlaNG #APT coverage with beacon traffic (2050902) and task request to controller (2050903) as well as multiple IOC-based signatures around involved domains (DNS SIDs 2050904-2050909) and associated TLS SNI connections (2050910-2050915) from @[talossecurity’s](https://twitter.com/talossecurity) release here:

> **[TinyTurla Next Generation - Turla APT spies on Polish NGOs](https://blog.talosintelligence.com/tinyturla-next-generation/)**
>
> This new backdoor we’re calling “TinyTurla-NG” (TTNG) is similar to Turla’s previously disclosed implant, TinyTurla, in coding style and functionality implementation.

And a last shout-out to our amazing @[threatinsight](https://twitter.com/threatinsight) team releasing their #bumblee blog - check out the referenced ET signature coverage!

> **[Security Brief: Bumblebee Buzzes Back in Black  | Proofpoint US](https://www.proofpoint.com/us/blog/threat-insight/bumblebee-buzzes-back-black)**
>
> What happened  Proofpoint researchers identified the return of Bumblebee malware to the cybercriminal threat landscape on 8 February 2024

That’s all for us - have a great weekend all!
