# Weekly Community Review - August 15, 2023

**URL:** https://community.emergingthreats.net/t/weekly-community-review-august-15-2023/893
**Category:** Announcements
**Created:** [August 23, 2023, 5:11pm UTC](https://community.emergingthreats.net/t/weekly-community-review-august-15-2023/893 "2023-08-23T17:11:57Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)
#### Post date: [August 23, 2023, 5:11pm UTC](https://community.emergingthreats.net/t/weekly-community-review-august-15-2023/893/1 "2023-08-23T17:11:57Z")

</div>

Greetings all - we had over 500 (574!!) rules added to our #etopen community ruleset. Again, thanks for the contributions on that score all, and I want to call out some of those that helped.

And lets remember - these #etopen rules are free. Yes, Free as in BSD licensed, which allows you to do what you like with them. All we ask is that when you have an idea, a new signature, feedback, or even just a theory, that you send it in to benefit everyone.  
[https://rules.emergingthreatspro.com/open/](https://rules.emergingthreatspro.com/open/)

Lots of rules added last week - and many of them from kind shares by - from this intel shared by [Cyber0verload](https://twitter.com/Cyber0verload) we added alerts for #Gamaredon #APT related DNS lookup alerts (2047084-2047112) and detections for TLS SNI traffic to same (2047126-2047154).

[https://twitter.com/Cyber0verload/status/1679757171469307904](https://twitter.com/Cyber0verload/status/1679757171469307904)

And for those DNS alerts and the TLS SNI when they fire - Since malware-related domains can be transitory these alerts are the beginning of an investigation - not the end. Triage them appropriately, dig-in to what you see from indicated hosts within your network(s), and good luck!

From @[MalGamy12](https://twitter.com/MalGamy12), alerts on #Agniane stealer exfil activity (SIDs 2047124) from shared hashes and intel here:

[https://twitter.com/MalGamy12/status/1688984207752663040](https://twitter.com/MalGamy12/status/1688984207752663040)

And more #Agniane stealer from @[ViriBack](https://twitter.com/ViriBack) - another exfil method covered with 2047492:

[twitter.com/ViriBack/status/1689447082040373249](http://twitter.com/ViriBack/status/1689447082040373249)

This domain share from Recorded Future enabled SIDs 2047162-2047251 (DNS alerts) and 2047252-2047341 (TLS SNI activity), thanks!

> **[GitHub - Insikt-Group/Research: Research indicators and detection rules](https://github.com/Insikt-Group/Research)**
>
> Research indicators and detection rules. Contribute to Insikt-Group/Research development by creating an account on GitHub.

Thanks to @[g0njxa](https://twitter.com/g0njxa) for this share of a @anyrun\_app run allowing us to model the patters and http body for alerting on this #stealer for SID 2047615:

[https://twitter.com/g0njxa/status/1677297278371889153](https://twitter.com/g0njxa/status/1677297278371889153)

Turning to our #Discourse - check it out! Such great discussion and wonderful sharing of intel, rule submissions, and FP reports. This @Jane0sint rule submission on #DarkCloud came from their analysis of an external IP check w/ a custom header allowing tight alert logic (SID 2047083)

> [@DarkCloud](https://community.emergingthreats.net/t/darkcloud/844/):
>
> Hi, I noticed that the darkcloud stealer requests an external ip address with a custom header, and I suggest detecting it with the following rule: alert http any any -\> any any (msg: "ET MALWARE [ANY.RUN] DarkCloud External IP Check"; flow: established, to\_server; http.method; content: "GET"; http.uri; content: "/"; urilen: 1; http.header; content: "User-Agent: Project1|0d0a|Host: showip.net"; depth: 38; isdataat: !3, relative; threshold: type limit, track by\_dst, seconds 300, count 1; re…

And read this full analysis of #StealC #Stealer which starts with a coverage hole, proceeds with anyrun forensics, iterates through multiple analytical steps and the resulting pcaps, and ends us up with 2047625 (checkin) and multiple payload request methods (2047626-2047627). This is great collaboration @Jane0sint !

> [@StealC Stealer](https://community.emergingthreats.net/t/stealc-stealer/856):
>
> Hello, I noticed a change in the stealer that was not yet covered by the rules. Here I propose a rule for check-in, no matter whether the server answers yes or no. Boundary features the number of bytes in hwid as well as two minus characters at the end of the post request are the detection conditions I propose. If you see fit, you can add a user agent. It is still the same as the URI. Here are two samples with different test and roza builds. alert http any any -\> any any (msg: "ET MALWARE [A…

From our own @[infosectimmy](https://twitter.com/infosectimmy), dozens of TLS SNI signatures (SID 2047479-2047491, 2047493-2047614) and DNS lookup alerts (SID 2047344-2047478) covering TOAD Domains! Not sure what TOAD is? Check it out here:

> **[The 411 on Call Center Scams & Fraud | Proofpoint US](https://www.proofpoint.com/us/blog/threat-insight/caught-beneath-landline-411-telephone-oriented-attack-delivery)**
>
> Call center scams are attempted tens of thousands of times daily. Proofpoint shares the role of call center threats in a sophisticated series of cyber attacks.

Lastly, shout-out to [@attcyber](https://twitter.com/attcyber) for the MacOS/Adload sigs SID 2047628 (C2 beacon), 2047629 & 2047630 (Proxy node beacons) and mentioning us in their blog [Mac systems turned into proxy exit nodes by AdLoad](https://cybersecurity.att.com/blogs/labs-research/mac-systems-turned-into-proxy-exit-nodes-by-adload)

Thanks all!
