# Weekly Community Review - February 24, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-february-24-2023/330>\
**Category:** Announcements\
**Created:** [February 25, 2023, 3:12am UTC](https://community.emergingthreats.net/t/weekly-community-review-february-24-2023/330 "2023-02-25T03:12:50Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [February 25, 2023, 3:12am UTC](https://community.emergingthreats.net/t/weekly-community-review-february-24-2023/330/1 "2023-02-25T03:12:50Z")

</div>

Greetings all, we are back with Free Sigs Friday and an overview of the week that was in ourSuricata IDS community - your help got us over the century mark with 102 (!) sigs added to ET Open this week - free for everyone to protect & defend your data. [https://rules.emergingthreatspro.com/open/](https://t.co/j7Vc3tNy6L)

Lets start with a link to our [Discourse FAQ page](https://community.emergingthreats.net/t/frequently-asked-questions/56) here and a bit on the differences between ET Open and ETPRO. ETPRO is our paid rule release - purely fed by intel, analysis, & insight from our internal Threat Research team & the great work they do every day.

ET Open is our community ruleset - these are sigs contributed by the community or signatures that are written by ET/Proofpoint based on community research. Feel free to drop us tips and samples runs on [twitter](https://twitter.com/ET_Labs), on our Discourse, or ask for a Discord invite!

That said, lets run through a few SIDs that wouldn’t exist without help like that. From [@crep1x](https://twitter.com/crep1x), SID 2044290, alerting on outbound activity indicating an Atlantida stealer POSTing out system information.

> <https://twitter.com/crep1x/status/1626280164547076100>
>
> crep1x @crep1x

From [@suyog41](https://twitter.com/suyog41), GurcuStealer aiding detection logic on exfiltration activity via a POST to telegram–SID 2044309 will alert!

> <https://twitter.com/suyog41/status/1628373761807511553>

Noticing a detection gap,[@StopMalvertisin](https://twitter.com/StopMalvertisin) tipping up a hash and [@cyb3rops](https://twitter.com/cyb3rops) correlating which enabled us to close that gap with SID 2044311, thank you!

> <https://twitter.com/StopMalvertisin/status/1628426658956075011>

And in the same thread,[@AzakaSekai\_](https://twitter.com/AzakaSekai_) tipping an associated C2 domain - this enabled SID 2044310 to alert for a DNS query against it.

> <https://twitter.com/AzakaSekai_/status/1628446258649235456>

Thanks to [@aRtAGGI](https://twitter.com/aRtAGGI) and [@Myrtus0x0](https://twitter.com/Myrtus0x0) and the great work they do within the Threat Research team, we got to tighten up detection in our Kumquat sigs, featured here:

> <https://twitter.com/aRtAGGI/status/1628067706443374592>
>
> Unit 42 @Unit42\_Intel

From [@c7rl4ltd3l](https://twitter.com/C7rl4ltD3l) and a [@urlscanio](https://twitter.com/urlscanio) [run](https://urlscan.io/result/26b88d69-0fea-4c63-9f29-3c53350c098e/), SIDs 2044318-2044322 modeling multiple stages of HiYu phishing activity.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/ebd7ce50d337478bdc14d5d040bcc27265fe3d49.png)

Publicly posted blogs and writeup help too. From [@_CPResearch_](https://twitter.com/_CPResearch_) [0xtaRAT C2 GET activity](https://research.checkpoint.com/2023/operation-silent-watch-desktop-surveillance-in-azerbaijan-and-armenia/), SIDs 2044261 and 2044291:

![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/74620c4071aaa797b63662abeff0a6d8dc899c0c.jpeg)

From [this](https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1) [@sekoia\_io](https://twitter.com/sekoia_io) writeup, SIDs 2044243-2044249 allowing us to alert on multiple Win32/Stealc intostealer activities.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/10bc9f28d6be24282fa96a15d09402d284228243.jpeg)

And finally, from [@TrendMicroRSRCH](https://twitter.com/TrendMicroRSRCH), [their writeup](https://www.trendmicro.com/en_us/research/23/b/earth-kitsune-delivers-new-whiskerspy-backdoor.html) on a new WhiskerSpy Backdoor allowed us to provide alerts on its activity from Machine Registration to data exfiltration - SIDs 2044250 to 2044256.

![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/27d7fd55880f471fed919b14483c4512ecaae033.jpeg)

One last bit - when possible we push out-of-band to get our detections out into the community ASAP. Tuesday, @James pushed 2044270 to address recently discovered ITW activity of CVE-2022-39952. We do our best to keep on top of active exploits and meet that challenge!

That’s all for this week - enjoy the weekend all!
