# Weekly Community Review - December 1, 2023

**URL:** https://community.emergingthreats.net/t/weekly-community-review-december-1-2023/1258
**Category:** Announcements
**Created:** [December 1, 2023, 6:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-december-1-2023/1258 "2023-12-01T06:00:00Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)
#### Post date: [December 1, 2023, 6:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-december-1-2023/1258/1 "2023-12-01T06:00:00Z")

</div>

Hello again! These past couple weeks have been a busy time here at [community.emergingthreats.net](http://community.emergingthreats.net), - and we’re very thankful for all the tips, submissions, and shared intelligence that allowed us to share 195 rules into the free community ETOpen ruleset. We wanted to take the time to go over a few of them so we might thank the contributors and show them just how much they’ve helped.

Keep in mind - these ETOpen rules are free. Free, as in BSD licensed, which allows you to do what you like with them. All we ask is that when you have an idea, a new signature, feedback, or even just a theory, that you send it in to benefit everyone. And you can do that [here](https://twitter.com/et_labs) on twitter, right here at our discourse site or by mailing us at support(at)emergingthreats(dot)net.

From @[StopMalvertisin](https://twitter.com/StopMalvertisin), this tweet featuring malicious domains rendered from the provided hash and intelligence allowed SIDs 2049283-2049284 (DNS queries for downloads) and the HTTP GET method and header content for SID 2049285 to alert on the imageres C2 payload request:

> <https://twitter.com/StopMalvertisin/status/1723310413541220372>

This @[AhnLab\_ASEC](https://twitter.com/AhnLab_ASEC) writeup discusses their investigation of #Andariel group activity stemming from what’s assumed to be exploitation of Apache ActiveMQ #CVE-2023-46604. SID 2049380 alerts on the Nukesped check-in thanks to the demonstrated potential HTTP header values:

> **[Circumstances of the Andariel Group Exploiting an Apache ActiveMQ...](https://asec.ahnlab.com/en/59318/)**
>
> AhnLab Security Emergency response Center

Thanks to @[threatinsight’s](https://twitter.com/threatinsight) Josh Miller for the tip-up on this shared intel, SIDs 2049410-2049411 cover SugarGh0st RAT domain lookups and 2049409 the Checkin activity alerting from the consistent heartbeat byte pattern shown here in this @[TalosSecurity](https://twitter.com/TalosSecurity) writeup :

> **[New SugarGh0st RAT targets Uzbekistan government and South Korea](https://blog.talosintelligence.com/new-sugargh0st-rat/)**
>
> Cisco Talos recently discovered a malicious campaign that likely started as early as August 2023, delivering a new remote access trojan (RAT) we dubbed “SugarGh0st.”

These releases from both @[_cpresearch_](https://twitter.com/_cpresearch_) and @[intezerlabs](https://twitter.com/intezerlabs) provided not only SysJoker Domain query alerts (SIDs 2049296-2049298) but allowed us to model observed UA strings (2049303 & 2049304), bot registration (2049302), config requests (2049301), infected host profile exfil (2049299), command exec success (2049300), and bot checkin (2049305).

> **[Israel-Hamas War Spotlight: Shaking the Rust Off SysJoker - Check Point Research](https://research.checkpoint.com/2023/israel-hamas-war-spotlight-shaking-the-rust-off-sysjoker/)**
>
> Key Findings Introduction Amid tensions in the ongoing Israel-Hamas war, Check Point Research has been conducting active threat hunting in an effort to discover, attribute, and mitigate relevant regional threats. Among those, some new variants of the...

> **[WildCard: The APT Behind SysJoker Targets Critical Sectors in Israel](https://intezer.com/blog/research/wildcard-evolution-of-sysjoker-cyber-threat/)**
>
> Our research team has identified a new APT group, dubbed “WildCard,” initially detected through its use of the SysJoker malware, which targeted Israel’s educational sector in 2021. WildCard has since expanded its reach, creating sophisticated malware...

From this @[JAMESWT\_MHT](https://twitter.com/JAMESWT_MHT) tweet and kind @[anyrun](https://twitter.com/anyrun_app) run RemCosRat domain alert SIDs 2049172-2049177

> <https://twitter.com/JAMESWT_MHT/status/1724401325734027567>

For those domain alert sigs, and really and disclosed IOC-based signature: these rules are created with a Time-To-Review value and within internal ET guidance a rule can be set to be permanent, be deferred for subsequent review, or be disabled. We don’t expect these domains to be forever viable for escalation. Investigate fires responsibly!

SID 2049408 was born from this @[Unit42\_Intel](https://twitter.com/Unit42_Intel) share - with an initial email vector, JinxLoader can lead to Formbook or other badness - this SID will fire on identified checkin traffic, as shown here:

> <https://twitter.com/Unit42_Intel/status/1730237085246775562/photo/4>

Multiple response deviations from the norm present in malicious HTTP servers are showcased in this @[foxit](https://twitter.com/foxit) blog, and SIDs 2049204-2049211 alerts on the differences documented within. Typos happen, but in these cases they should be investigated.

> **[The Spelling Police: Searching for Malicious HTTP Servers by Identifying...](https://blog.fox-it.com/2023/11/15/the-spelling-police-searching-for-malicious-http-servers-by-identifying-typos-in-http-responses/)**
>
> Authored by Margit Hazenbroek At Fox-IT (part of NCC Group) identifying servers that host nefarious activities is a critical aspect of our threat intelligence. One approach involves looking for ano…

Lots of activity covered by new SIDs from this @[eSentire](https://twitter.com/eSentire) fake QuickBooks TOAD scam writeup. With a phone session with a bogus “support” person as a vector, successful infections are detailed and allowed SIDs 2049221-2049222 (request for dload locations& response), 2049226 & 2049223 (checkin/response), and 2049224-2049225 (details request/response):

> **[Threat Actors Using Fake QuickBooks Software to Scam Organizations](https://www.esentire.com/blog/threat-actors-using-fake-quickbooks-software-to-scam-organizations)**
>
> Learn more about how threat actors are using a malicious Quickbooks accounting software application to target users into downloading malware and get security recommendations from our Threat Response Unit (TRU) to protect your business from this cyber...

Here, @g0njxa @Jane0sint share #vidar #Stealer insights - leading to observation of a new TLS certificate in use and a new alert (SID 2049253) on its presentation:

> [@Vidar Stealer](https://community.emergingthreats.net/t/vidar-stealer/1106):
>
> This is going to be controversial. Vidar Stealer made a 180 degree change in their C2 traffic. This is the official statement from their panel both in Russian (original) and English (Translated) 6.4 — Большое обновление софтовой части Переписана полностью вся кодовая часть софта. Теперь отправка лога осуществляется частями(пофайлово). За счёт пофайловой отправки улучшили отстук порядка +15-20 процентов. Улучшили рантайм. Улучшили валидность гугла. Улучшили определение дубликатов (добавили нов…

We love sig submissions! User @kevross33 with this Turla #APT #C2 activity firing on observed malicious HTTP POST content. It’s SID 2049264:

> [@New Sig: ET TROJAN W32/Kazuar.Backdoor Turla APT Hardcoded Cookie](https://community.emergingthreats.net/t/new-sig-et-trojan-w32-kazuar-backdoor-turla-apt-hardcoded-cookie/1136/2):
>
> hey @kevross33, thanks for the rule submission! Here is the final rule that went out in today’s release. partying_face alert http $HOME\_NET any -\> $EXTERNAL\_NET any (msg:"ET MALWARE Turla APT/Kazuar Backdoor CnC Activity (POST)"; flow:established,to\_server; http.method; content:"POST"; http.uri; content:".php"; endswith; http.cookie; content:"AspNet.Cookies=MTY5NzM5ZTcyMTEyOTUxNDZhNjFkMzAwYzBmZWYwMmQ="; bsize:59; fast\_pattern; http.request\_body; content:"|3c|"; depth:1; content:"|3e 3c|"; ref…

From @g0njxa , a kind tip up on @[AnFam17](https://twitter.com/AnFam17)’s #MetaStealer work - this became SID 2049282 - check out the collaboration and citation that happens within this #infosec community - it’s wonderful!

> [@Meta vs Redline Stealer](https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141/1):
>
> Meta Stealer has been around since 2022 and has been used very frequently by TA in the stealers market. Somehow and because of C2 traffic similarities on Redline and Meta builds, this second has been “forget” by malware analysts and hunters, under the Redline name. Recently, Threat Intelligence Researcher @AnFam17 has made an amazing report on this stealer: [MetaStealer - Redline’s Doppelgänger (russianpanda.com)](https://russianpanda.com/2023/11/20/MetaStealer-Redline's-Doppelganger/) So we finally can start digging into Meta stealer and its detection. Meta should…

> **[MetaStealer - Redline's Doppelgänger](https://russianpanda.com/2023/11/20/MetaStealer-Redline's-Doppelganger/)**
>
> MetaStealer malware analysis

And this site isn’t just for sig submissions - we take FP reports as well! Here, @Jane0sint gives us a kind alert that #etpro SID 2825567 is a little too loud - this Lets Encrypt SSL Cert alert is now disabled.

> [@FP: ETPRO TROJAN Possible Panda Banker DGA Lets Encrypt SSL Cert \[2825567\]](https://community.emergingthreats.net/t/fp-etpro-trojan-possible-panda-banker-dga-lets-encrypt-ssl-cert-2825567/1168):
>
> Hi, could you please revise this rule? It match certs on public tasks, making it difficult to detect phishing. Sometimes collectorstealer matches as panda. Here is submissions by tag:pandabanker arrow_heading_down I searched for information on this threat and didn’t find anything earlier than 2 years ago, it may happen that it is no longer relevant. Jane ﾟ𐦍༘⋆

It’s all about helping the community - user @prime69 asks after signature reference content and ET staff and community users spring into action - stop by and be a part of it.

> [@ET Malware - Socks5Systemz](https://community.emergingthreats.net/t/et-malware-socks5systemz/1155):
>
> hi Team Emerging Threats can please advise where can i get more information about below rule name ET MALWARE Socks5Systemz CnC Checkin M2 need a site that can give me a deep dive into malware analysis and understanding its impact via real world scenarios hit by such a malware focusing on volume and financial losses from such a malware Thanks

That’s it for us this week all - be well and enjoy the weekend.
