# Weekly Community Review - April 21, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-april-21-2023/502>\
**Category:** Announcements\
**Created:** [April 24, 2023, 8:10pm UTC](https://community.emergingthreats.net/t/weekly-community-review-april-21-2023/502 "2023-04-24T20:10:49Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [April 24, 2023, 8:10pm UTC](https://community.emergingthreats.net/t/weekly-community-review-april-21-2023/502/1 "2023-04-24T20:10:49Z")

</div>

Last week here ended with snow yesterday–and with 271 (!) additional rules for ET Open! Thanks go to the wonderful sharing efforts within our [#infosec](https://twitter.com/hashtag/infosec?src=hashtag_click) [#Suricata](https://twitter.com/hashtag/Suricata?src=hashtag_click) [#IDS](https://twitter.com/hashtag/IDS?src=hashtag_click) Community as they were built from that intel & the moving of several PRO rules to Open! Lets chat on a few…

First, lets talk about ET Open - they’re free! Free, as in BSD licensed, which allows you to do what you like with them. All we ask is that when you have an idea, a new signature, feedback, or even just a theory, that you send it in to benefit everyone.

And how do you do that? On our [twitter](https://twitter.com/et_labs), here on [Discourse](https://community.emergingthreats.net), on our mailing list via support[at]emergingthreats[dot]net, or on our Discord (hit us up via DM for an invite!).

And I mentioned ETPRO rules moving to open…check out our [FAQ](https://community.emergingthreats.net/t/frequently-asked-questions/56) for the answers to how that can happen as well as get insight on several other questions you might have. Or ask your own!

Back to the sigs - continued [#Gamaredon](https://twitter.com/hashtag/Gamaredon?src=hashtag_click) [#APT](https://twitter.com/hashtag/APT?src=hashtag_click) shares from [@Cyber0verload](https://twitter.com/Cyber0verload)- thanks for the tags, they’re much appreciated, and they led to SIDs 2044994-2044997 (DNS alerts) as well as 2044353 alerting on outbound GET activity.

[https://twitter.com/Cyber0verload/status/1628673516177596417](https://twitter.com/Cyber0verload/status/1628673516177596417)

Friend [@Jane\_0sint](https://twitter.com/Jane_0sint) tagged us in on a thread with [@crep1x](https://twitter.com/crep1x) and [@James\_inthe\_box](https://twitter.com/James_inthe_box) on what we called [#LeftHook](https://twitter.com/hashtag/LeftHook?src=hashtag_click) [#Stealer](https://twitter.com/hashtag/Stealer?src=hashtag_click) - SIDs 2044999, 2045002-2045006 on its various C2 activities:

[https://twitter.com/Jane\_0sint/status/1648075834702413830](https://twitter.com/Jane_0sint/status/1648075834702413830)

And from that same thread,[@crep1x](https://twitter.com/crep1x) with SID 2045000 on the inbound connection check response - [#RedLine](https://twitter.com/hashtag/RedLine?src=hashtag_click) [#Stealer](https://twitter.com/hashtag/Stealer?src=hashtag_click) in our Attack\_Response [#Suricata](https://twitter.com/hashtag/Suricata?src=hashtag_click) category.

[https://twitter.com/crep1x/status/1648063045808148481](https://twitter.com/crep1x/status/1648063045808148481)

For [#Suricata](https://twitter.com/hashtag/Suricata?src=hashtag_click) “Attack Response”, these are sigs that identify responses indicative of intrusion, results of a successful attack, and scripts (including common obfuscation methods) used in the delivery of malware or other malicious payloads.

> [@Current Suricata 5 and Suricata 6 Rule Categories](https://community.emergingthreats.net/t/current-suricata-5-and-suricata-6-rule-categories/94):
>
> ET features over 50 categories which may be assigned to individual signatures. These categories are assigned as signatures are created and updated. To help understand how these category names are selected and attributed to each signature, below is a list of definitions for each category. 3CORESec–This category is for signatures that are generated automatically from the 3CORESec team’s IP block lists. These blocklists are generated by 3CORESec based on malicious activity from their Honeypots. …

Back to the action! [@ViriBack](https://twitter.com/ViriBack) with a kind tag for 3 [#Nemesis](https://twitter.com/hashtag/Nemesis?src=hashtag_click) domains - these are DNS lookup alerts within SIDs 2045035-2045037. Thanks!

[https://twitter.com/ViriBack/status/1647664120374730755](https://twitter.com/ViriBack/status/1647664120374730755)

Another great tag to us from [@MavericksInt](https://twitter.com/MavericksInt), thanks much for Hunting SIDs 2045046 and 2045047 for potential [#Gamaredon](https://twitter.com/hashtag/Gamaredon?src=hashtag_click) activity:

[https://twitter.com/MavericksInt/status/1648246438982287360](https://twitter.com/MavericksInt/status/1648246438982287360)

From [@Yeti\_Sec](https://twitter.com/Yeti_Sec), a [@urlscanio](https://twitter.com/urlscanio) layout allowing us to alert on the incoming push of a [#Nemesis](https://twitter.com/hashtag/Nemesis?src=hashtag_click) admin panel in SID 2045055!

[https://twitter.com/Yeti\_Sec/status/1648670765116522496](https://twitter.com/Yeti_Sec/status/1648670765116522496)

For some housekeeping this week, shout-out to [@500mk500](https://twitter.com/500mk500), [@Gi7w0rm](https://twitter.com/Gi7w0rm),[@StopMalvertisin](https://twitter.com/StopMalvertisin),  
[@threatinsight](https://twitter.com/threatinsight)’s own [@greglesnewich](https://twitter.com/greglesnewich), and [@TLP\_R3D](https://twitter.com/TLP_R3D) who all helped us tidy up some mis-attribution and FP’ing signatures - all your feedback helps us do what we do!

On the industry side, this [@HuntressLabs](https://twitter.com/HuntressLabs) post enabled SIDs 2045131-2045139 - these are alerts on activity to post-exploit domains from [#PaperCut](https://twitter.com/hashtag/PaperCut?src=hashtag_click).

> **[Critical Vulnerabilities in PaperCut Print Management Software](https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software)**
>
> Our team is tracking in-the-wild exploitation of zero-day vulnerabilities against PaperCut MF/NG which allow for unauthenticated remote code execution due to an authentication bypass.

From Google TAG - a [#Sandworm](https://twitter.com/hashtag/Sandworm?src=hashtag_click) report on [#Russia](https://twitter.com/hashtag/Russia?src=hashtag_click) focusing on [#Ukraine](https://twitter.com/hashtag/Ukraine?src=hashtag_click) rendered DNS alerting on SIDs 2045110-2045120 for the associated IOCs within:

> **[Ukraine remains Russia’s biggest cyber focus in 2023](https://blog.google/threat-analysis-group/ukraine-remains-russias-biggest-cyber-focus-in-2023/)**
>
> Google's Threat Analysis Group shares first quarter cyber updates on the threat landscape from the war in Ukraine.

A regular reminder on IOC sigs: - since items like domains can be transitory these rules are created with a Time-To-Review value and within those points a rule can be set to be permanent, be deferred for review, or be disabled. Investigate fires responsibly!

Lastly, from our friends at [@nao\_sec](https://twitter.com/nao_sec), further SIDs from their report on compromised sites using fake Chrome errors to push malware, 2045127-2045129.

[https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com](https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com)
