# Weekly Community Review - January 27, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-january-27-2023/287>\
**Category:** Announcements\
**Created:** [January 27, 2023, 11:43pm UTC](https://community.emergingthreats.net/t/weekly-community-review-january-27-2023/287 "2023-01-27T23:43:46Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [January 27, 2023, 11:43pm UTC](https://community.emergingthreats.net/t/weekly-community-review-january-27-2023/287/1 "2023-01-27T23:43:46Z")

</div>

Greetings all! Powered by your contributions and publicly available information we had almost 600 (!!) Suricata IDS rules added to ET Open this week. Here’s a breakdown…

Almost 500 of those signatures were INFO signatures alerting on outbound queries over HTTP from servers documented here: [DNS over HTTPS · curl/curl Wiki · GitHub](https://github.com/curl/curl/wiki/DNS-over-HTTPS). It’s important to note: These are INFO sigs and their alerts are not indicative of maliciousness outside other contextual evidence!

We’ve also had SIDs 2043439-2043453 on Gigabud RAT derived from information posted by [@AuCyble](https://twitter.com/AuCyble), on this blog:[http://blog.cyble.com/2023/01/19/gigabud-rat-new-android-rat-masquerading-as-government-agencies/](https://t.co/NsJvf5xx5p)

Thanks to [@James\_inthe\_box](https://twitter.com/James_inthe_box) for [https://twitter.com/James\_inthe\_box/status/1618370975523012608…](https://twitter.com/James_inthe_box/status/1618370975523012608), giving us SID 2044001…

SID 2043986, outbound POST to a c2 [here](https://twitter.com/1ZRR4H/status/1617580483550015488), thanks [@1ZRR4H](https://twitter.com/1ZRR4H)!

From [@jaydinbas](https://twitter.com/jaydinbas), thanks for the tag which rendered SID 2043987, outbound connection using a suspect UA string associated with Win32/DoNot.

a [@TrendMicro](https://twitter.com/TrendMicro) blog, [https://trendmicro.com/en\_us/research/23/a/vice-society-ransomware-group-targets-manufacturing-companies.html…](https://t.co/tdROReJfVu), giving us [#cobaltstrike](https://twitter.com/hashtag/cobaltstrike?src=hashtag_click) C2s and SIDS 2043988-2043990.

For exploits,[@bl4sty](https://twitter.com/bl4sty)’s work here: [http://github.com/blasty/lexmark](https://t.co/Z1VxyQy0rJ) enabling community detection for his discovered Lexmark vulnerability.

Our friends at [@TheDFIRReport](https://twitter.com/TheDFIRReport), posting [http://thedfirreport.com/2023/01/09/unwrapping-ursnifs-gifts…](https://t.co/LbIRinrcHf) and giving us SID 2043996, “ET INFO Suspected Impacket WMIExec Activity”

And lets talk about tuning! After some noise report, we put tune of 2031193 - ET MALWARE Suspected Snugy DNS Backdoor Initial Beacon. Intial writeup was done by Unit42 ([https://unit42.paloaltonetworks.com/xhunt-campaign-backdoors/…](https://t.co/Z4FBibtMBs))…

Using the reference sample, (can be observed in this [http://any.run](https://t.co/K9C32HpYPk) [https://app.any.run/tasks/9031305c-0ad3-4c07-804a-3d913251ad4b/…](https://t.co/cNb3rlq3eA)) our own @bmurphy stripped out everything not doing with the DGA for that initial checkin, then used “Try It Online” ([@try\_it\_online](https://twitter.com/Try_It_Online)) to run the code…

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/d022fb2732c4a1b902e0c5de261b21047d9bd54f.png)

With the output of over 100 domains, using regex101 ([@regex101](https://twitter.com/regex101)) a new pattern was found which allowed for a tighter PCRE to detect the initial checkin subdomains! Less FPs! Victory!

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/b3293536c52fddeb26f8641e866dc5a048836fd9.jpeg)

And lastly for today, wonderful work by [@greglesnewich](https://twitter.com/greglesnewich) on the [@threatinsight](https://twitter.com/threatinsight) #TA444 blog here, including free community ET Open sigs alerting on associated domains! Have a great weekend all!
