# Weekly Community Review - December 22, 2023

**URL:** https://community.emergingthreats.net/t/weekly-community-review-december-22-2023/1228
**Category:** Announcements
**Created:** [December 22, 2023, 10:02pm UTC](https://community.emergingthreats.net/t/weekly-community-review-december-22-2023/1228 "2023-12-22T22:02:22Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)
#### Post date: [December 22, 2023, 10:02pm UTC](https://community.emergingthreats.net/t/weekly-community-review-december-22-2023/1228/1 "2023-12-22T22:02:22Z")

</div>

Greetings all! As we close off 2023 we wanted to talk about some recent contributions to the #etopen #suricata and Snort rulesets and thank everyone who not only tips us up about new detection possibilities but gives us feedback on those detections we have within the sets already.

You can reach us on [twitter](https://twitter.com/et_labs) of course - but there’s other options too. Here on our Discourse site ([community.emergingthreats.net](http://community.emergingthreats.net)) and mail alias support(at)emergingthreats(dot)net are great options too. We’ve also got a #Discord channel - DM us here for an invite!

It’s been quite a busy year for Exploits and because of that we are challenged to provide #IDS coverage however we can. We don’t do this alone - our APT and Crimeware teams are always hard at work collaborating with us on Intel and identified TTPs. We have over 6,000 rules in the ruleset focused on documented CVE alone!

Here, SIDs 2049617 and 2049618 cover the attempted and subsequently successful exploit of ownCloud CVE-2023-49105 - a vulnerability which when exploited can lead to privilege escalation, and remote code execution! Thanks to this @[ambionics](https://twitter.com/ambionics) blog:

> **[Owncloud: details about CVE-2023-49103 and CVE-2023-49105](https://www.ambionics.io/blog/owncloud-cve-2023-49103-cve-2023-49105)**
>
> We provide details about CVE-2023-49103 and CVE-2023-49105

This @[anyrun\_app](https://twitter.com/anyrun_app) post lent the SSL Cert content for #BrushaLoader - SID 2049634 will alert you on the presentation of this malicious cert during the TLS connection!

> <https://twitter.com/anyrun_app/status/1731656654008000859>

Speaking of #IOC-based signatures, this @[talossecurity](https://twitter.com/talossecurity) #TA430 writeup contains #Andariel network intelligence we were able to craft into DNS (2049652 & 2049654) query and TLS SNI presentation (2049653 & 2049655) as well as technique/activity-based #POST (2049656) coverage as well! Thanks @[greglesnewich](https://twitter.com/greglesnewich) for the tip!

> **[Operation Blacksmith: Lazarus targets organizations worldwide using novel...](https://blog.talosintelligence.com/lazarus_new_rats_dlang_and_telegram/)**
>
> Our latest findings indicate a definitive shift in the tactics of the North Korean APT group Lazarus Group.

From the Ukrainian CERT (@[\_CERT\_UA](https://twitter.com/_CERT_UA)) SIDs 2049743-2049767 (DNS queries) 2049768-2049792 (TLS SNI) for #UAC-0177. Thanks [https://twitter.com/bry\_campbell](https://twitter.com/bry_campbell)!

> **[CERT-UA](https://cert.gov.ua/article/6276799)**
>
> Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.

We mentioned our Discord before, thanks to @[viriback](https://twitter.com/viriback) for directly sharing the anyrun generated pcaps for BlackRain coverage - both c2 (2049802) and observed UA string (2049803) are from that kind share!

Friend @[suyog41](https://twitter.com/suyog41) with some Axile Stealer intel shared in this tweet - we’ve got the full outbound chain here! A DNS query (2049687), TLS connection (2049688), then the c2 for exfiltration via telegram (2049689)! If you see these firing in concert within your monitored environments, check it out.

[https://twitter.com/c/status/1734227876604784777](https://twitter.com/c/status/1734227876604784777)

Here on our #Discourse it’s not just a place for rule submissions. We appreciate feedback too! Here, friend @Jane0sint identifies an issue with rule messages - and @ishaughnessy dips in to make it right!

> [@Inconsistency between the rules 2049660 & 2049661 and the family](https://community.emergingthreats.net/t/inconsistency-between-the-rules-2049660-2049661-and-the-family/1219/1):
>
> Hi, there seems to be a little confusion with signatures 2049660 & 2049661, the fact is that it was written in RisePro because the magic and the encrypted bytes 0x36 match its traffic. Best regards, Jane ˶ᵔ ᵕ ᵔ˶

But wait - there’s more! As we work with #suricata we use our platforms to educate as well. Here, our own @bingohotdog shares some tips around troubleshooting your #opensource #IDS analysis:

> [@Get Started with Suricata CLI Debugging](https://community.emergingthreats.net/t/get-started-with-suricata-cli-debugging/1195):
>
> Let’s review how to debug Suricata rules from the command line. If you want to troubleshoot your rules or the Suricata engine itself, then CLI debugging is an invaluable skill to have! The following Suricata bug inspired the material below, [Bug #6415: http: various header buffer not populated when malformed header value exists - Suricata - Open Information Security Foundation](https://redmine.openinfosecfoundation.org/issues/6415). No fancy setup here, just a quick guide that is hopefully accessible for all. Steps for Linux Users Whenever Suricat…

From friend @[g0njxa](https://twitter.com/g0njxa), SID 2049812 alerts on outbound #Lumma #Stealer activity based on identified method (http POST) and content from the provided anyrun and virustotal correlative models for detection!

[https://twitter.com/g0njxa/status/1737123594054906114](https://twitter.com/g0njxa/status/1737123594054906114)

This @[reecdeep](https://twitter.com/reecdeep) #TA577 (and referenced anyrun run) led us to SIDs 2049708-2049713 alerting on the presence of malicious SSL certs during the TLS handshake connection process:

[https://twitter.com/reecdeep/status/1735649391447302362](https://twitter.com/reecdeep/status/1735649391447302362)

And wrapping up, this recent @[threatinsight](https://twitter.com/threatinsight) #Darkgate blog featuring a mail vector, identified TTPs, and RogueRaticate FakeBrowser activity includes #etopen Community signatures for WebDAV potentially malicious file grabs, Downloader and Checkin coverage, and NetSupport RAT activity!

> **[BattleRoyal, DarkGate Cluster Spreads via Email and Fake Browser Updates ...](https://www.proofpoint.com/us/blog/threat-insight/battleroyal-darkgate-cluster-spreads-email-and-fake-browser-updates)**
>
> Overview  Throughout the summer and fall of 2023, DarkGate entered the ring competing for the top spot in the remote access trojan (RAT) and loader category. It was observed in use by

Have a joyful holiday all - #EmergingThreats is back with rule releases Tuesday, December 26.
