# Community Review - May 31, 2024

**URL:** <https://community.emergingthreats.net/t/community-review-may-31-2024/1775>\
**Category:** Announcements\
**Created:** [May 31, 2024, 5:00am UTC](https://community.emergingthreats.net/t/community-review-may-31-2024/1775 "2024-05-31T05:00:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [May 31, 2024, 5:00am UTC](https://community.emergingthreats.net/t/community-review-may-31-2024/1775/1 "2024-05-31T05:00:00Z")

</div>

Greetings all! We’re back today to talk about the importance of #community contributions to ET! Our ET Open ruleset ([Proofpoint Emerging Threats Rules](https://rules.emergingthreatspro.com/open/)) is available free to download and part of #suricata’s default configuration. Your tip-ups to us get turned into rules that are out there helping our infosec community. Here’s a few recent shares:

From @[0xrb](https://twitter.com/0xrb) on twitter, the shared hashes on #CrimsonRAT informed not only an alert against a DNS query for an involved domain (SID 2052908) and the TLS handshake (2052910) but byte-pattern content matching on enumerated infected host file paths on the outbound exfiltration activity (2052908).

> <https://twitter.com/0xrb/status/1795362130281324685>

Friend @[suyog41](https://twitter.com/suyog41) with hash shares on TA450 MuddyWater APT - SID 2052911 alerts on the outbound activity from an infected host crafted from the UA string observed!

[twitter.com.com/suyog41/status/1793935723961143625](http://twitter.com.com/suyog41/status/1793935723961143625)

Not only SIDs alerting on lookups against the domain involved (2052802) and the TLS handhsake (2052803) but both inbound (2052805) and outbound (2052804) #Winnti activity from these hash and @hatching\_triage and @app\_any\_run sandbox runs from @[naumovax](https://twitter.com/naumovax)!

> <https://x.com/naumovax/status/1792902386295394629>

Many thanks as always to friend of ET @[travisbgreen](https://twitter.com/travisbgreen) for his FP tips, particularly one that helped us tighten up SID 2000488. You can help us out too! Give us a shout out on [twitter](https://twitter.com/et_labs), at support (at) [emergingthreats.net](http://emergingthreats.net), or here on our discourse site: [https://community.emergingthreats.net/](https://community.emergingthreats.net/)

ET Contributor @cosmicgumbo helped out with his ETOpen submissions related to OpenTSDB RCEs. Sigs 2052823-2052825 covering different inbound methods attempting command injection #CVE\_2023\_25826 are now in the ruleset!

> **[OpenTSDB 2.4.1 Unauthenticated Command Injection ≈ Packet Storm](http://packetstormsecurity.com/files/174570/OpenTSDB-2.4.1-Unauthenticated-Command-Injection.html)**
>
> Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers

Friend of ET @jt42 contributed SID 2052949 - this alerts on observed #Smokeloader outbound Payload activity

SID 2053200 came from these @[JAMESWT\_MHT](https://twitter.com/JAMESWT_MHT) and @[c\_APT\_ure](https://twitter.com/c_APT_ure) tweets - it alerts on the #AgentaTesla download activity outbound:

> <https://x.com/JAMESWT_MHT/status/1796494582022394359>

This @[malware\_traffic](https://twitter.com/malware_traffic) writeup cites @[rerednawyerg](https://twitter.com/rerednawyerg) provided samples for us to detonation and model for SID 2052950 triggering on the unique URI pattern identified in the GET and the obserfved UA string in-use:

[https://www.malware-traffic-analysis.net/2024/03/14/index.html](https://www.malware-traffic-analysis.net/2024/03/14/index.html)

We love our Discourse community here - it’s not just a place where you can get support but you can submit rules for addition to ETOpen as well. Check out these two submission from user @kevross33 : W32/Badspace.Backdoor. These became outbound alerting SIDs 2052557 (C2 GET) and 2052558 (C2 POST).

> [@SIGS: W32/Badspace.Backdoor](https://community.emergingthreats.net/t/sigs-w32-badspace-backdoor/1630):
>
> Hi, Here is a backdoor I have given a temporary name based on the error in the user agent of extra space as all AV names are generic. You can get the PCAP from [&nbsp;6a195e6111c9a4b8c874d51937b53cd5b4b78efc32f7bb255012d05087586d8f | Triage](https://tria.ge/240430-s7lnpacb59/behavioral1). The POST body is obsucated/encrypted as is the results of the base64 cookie value but the user agent is a good but very specific match given the error they have made (Mozilla / 4.0 ). alert tcp $HOME\_NET any → $EXTERNAL\_NET $HTTP\_PORTS (msg:“ET TROJAN W32/Badspa…

We find value in IOC-based signatures as well - and these are powered by researchers and industry partners relaying their findings and laying them bare for all of us to alert against. Here, @[karol\_paciorek](https://twitter.com/karol_paciorek) shares multiple Remcos domains. For SIDs 2052849-2052858 we keep an eye on their continued activity and assign a TTR (time-to-review) that ensures our ruleset stays accurate and relevant!

> <https://x.com/karol_paciorek/status/1793596358819274815>

On the homefront, great work by the @[threatinsight](https://twitter.com/threatinsight), @[infosectimmy](https://twitter.com/infosectimmy) and @[selenalarson](https://twitter.com/selenalarson) prove that anything, even a ‘free’ piano, can be used to scam victims into falling for #AFF #scams.

> **[Security Brief: Sing Us a Song You’re the Piano Scam  | Proofpoint US](https://www.proofpoint.com/us/blog/threat-insight/security-brief-sing-us-song-youre-piano-scam)**
>
> What happened  Proofpoint recently identified a cluster of activity conducting malicious email campaigns using piano-themed messages to lure people into advance fee fraud (AFF) scams. The campaigns...

And lastly, give a listen to the #Discarded podcast, as it returns into inform and progress the state of #infosec knowledge forward!

“Decrypting Cyber Threats: Tactics, Takedowns, and Resilience” by Proofpoint via #spreaker: [Decrypting Cyber Threats: Tactics, Takedowns, and Resilience](https://www.spreaker.com/episode/decrypting-cyber-threats-tactics-takedowns-and-resilience--60201178)
