# Weekly Community Review - January 19, 2024

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-january-19-2024/1310>\
**Category:** Announcements\
**Created:** [January 19, 2024, 6:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-january-19-2024/1310 "2024-01-19T06:00:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [January 19, 2024, 6:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-january-19-2024/1310/1 "2024-01-19T06:00:00Z")

</div>

Greetings all! We’re back to talk about all the kind contributions to our ET Open #IDS #suricata and #Snort rulesets recently. As a reminder, we work to address threats on the landscape and construct detection logic from public disclosures (which go into ET Open) and the analysis (including malware reversing) of internally sourced samples and research (which go into ETPRO).

There are multiple ways to share with us - on [twitter](https://twitter.com/et_labs), on our Discord server (ask for an invite), here on our community discourse page ([https://community.emergingthreats.net/](https://community.emergingthreats.net/)), our mail alias (support at [emergingthreats.net](http://emergingthreats.net)), our feedback forum ([Feedback](https://feedback.emergingthreats.net/feedback)) or our new mastadon page ([EmergingThreats (@EmergingThreats@infosec.exchange) - Infosec Exchange](https://infosec.exchange/@EmergingThreats))

A bunch of researchers have helped us recently, and we’d love to give them some kudos. From @[malwrhunterteam](https://twitter.com/malwrhunterteam) off a @[MsftSecIntel](https://twitter.com/MsftSecIntel) share, this hash and analysis led to an additional method covered for #FalseFont backdoor within SID 2049963:

> <https://twitter.com/malwrhunterteam/status/1744660043574698176>
>
> Microsoft Threat Intelligence @MsftSecIntel

Old from of ET @tgreen shared this @[foxit](https://twitter.com/foxit) #blister writeup which contained CS C2 profiles for us to add to our detection coverage (SIDs 2049975-2049995) - these profiles exist to obfuscate C2 traffic, but our detections exist to thwart them!

> **[Popping Blisters for research: An overview of past payloads and exploring...](https://blog.fox-it.com/2023/11/01/popping-blisters-for-research-an-overview-of-past-payloads-and-exploring-recent-developments/)**
>
> Authored by Mick Koomen Summary Blister is a piece of malware that loads a payload embedded inside it. We provide an overview of payloads dropped by the Blister loader based on 137 unpacked samples…

Thanks to @[asdasd13asbz](https://twitter.com/asdasd13asbz) and @[jaydinbas](https://twitter.com/jaydinbas) for these shares (h/t @[greglesnewich](https://twitter.com/greglesnewich)) allowing us to sig #TrollAgent domains alerting on on DNS lookup (SIDs 2049955, 2049962, 2049967-2049969) and TLS SNI connection alerts (2049970-2049973)

> <https://twitter.com/jaydinbas/status/1744288770524918119>
>
> hithere @asdasd13asbz

#SeaTurtle #APT checkin coverage in SID 2049974 from this @[huntandhackett](https://twitter.com/huntandhackett) blog (h/t @[threatinsight’s](https://twitter.com/threatinsight) Josh Miller!)

> **[Turkish espionage campaigns in the Netherlands](https://www.huntandhackett.com/blog/turkish-espionage-campaigns)**
>
> Turkish Advanced Persistent Threat (APT) actor Sea Turtle is believed to have orchestrated cyberattacks against the Netherlands

Friend @[naumovax](https://twitter.com/naumovax) shares this @[SonicWall](https://twitter.com/SonicWall) blog on this sneaky #CoinMiner framework masquerading as a game trainer for #Rust. SID 2050052 has the outbound C2 activity covered!

> **[Steam - Rust Trainer, DGA & Miner Found | SonicWall](https://blog.sonicwall.com/en-us/2019/10/steam-rust-trainer-dga-miner-found/)**
>
> Overview: SonicWall Capture Labs Threat Research Team, recently found a unique Domain Generation Algorithm (DGA) inside a uniquely named file called “Rust Trainer.exe” the sample goes along with the Steam, PC Game called “(RUST)”. The \[…\]

So many researchers and orgs sharing and helping us out - special thanks to @[attcyber](https://twitter.com/attcyber) and more specifically @[siderafer](https://twitter.com/siderafer) / Fernando Martinez for AsyncRAT research and detection aid!

We mentioned our #Discord earlier - friend @[ViriBack](https://twitter.com/ViriBack) teed up a hash and Virustotal analysis for #Neptune #Loader that became SID 2050109!

Thanks to @[1ZRR4H](https://twitter.com/1ZRR4H) and their share of this @[sucurisecurity](https://twitter.com/sucurisecurity) writeup - this enabled SIDs on DNS alerts (2050134 and 2050136) and TLS SNI connections (2050135 and 2050137) for identified #Balada domains as well as SID 2050138 catching on the JavaScript injection on a vulnerable page using #PopupBuilder!

> **[Thousands of Sites with Popup Builder Compromised by Balada Injector](https://blog.sucuri.net/2024/01/thousands-of-sites-with-popup-builder-compromised-by-balada-injector.html)**
>
> Balada Injector has exploited a known XSS vulnerability in the Popup Builder plugin to compromise thousands of websites. Learn how to spot the attack and follow steps to mitigate risk and protect your site.

Friend @[naumovax](https://twitter.com/naumovax) linking multiple sandbox runs allowed SIDs 2050230 (client checkin) and 2050229 (C2 server response) for #AdAptertrAin #backdoor. Check out their featured Base64 ‘encrypted’ traffic: it’s sending profile information for the compromised host back to its controller.

> <https://twitter.com/naumovax/status/1747985922098966617>

Lots happening here on our #Discourse always - here friend @Jane0sint shares #XenoRAT traffic and @app\_anyrun analysis which allows us to model the check-in (2050110) and keep-alive (2050111) outbound activity:

> [@Xeno-RAT](https://community.emergingthreats.net/t/xeno-rat/1290/2):
>
> Thanks @Jane0sint! We’ll get these in today’s release. I’ll let you know what the sids are when I have them. tada

Don’t forget to check out @[dansomware](https://twitter.com/dansomware) and @[adorais](https://twitter.com/adorais) on the lastest #Discarded podcast talking about their 2024 cyber threat predictions!

> **[Phishing, Elections, and Costly Attacks: Part One of Predicting Cyber Threats...](https://www.spreaker.com/episode/phishing-elections-and-costly-attacks-part-one-of-predicting-cyber-threats-in-2024--58227436)**
>
> To move forward, it’s good to take a minute and reflect on what’s happened. 
> 
> Today’s episode focuses on insights from Daniel Blackford and mailto:adoraisjoncas@proofpoint.com, both Senior Managers of Threat Research at Proofpoint. This is the first...

Thanks all!
