# Weekly Community Review - June 16, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-june-16-2023/715>\
**Category:** Announcements\
**Created:** [July 3, 2023, 1:26pm UTC](https://community.emergingthreats.net/t/weekly-community-review-june-16-2023/715 "2023-07-03T13:26:58Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [July 3, 2023, 1:26pm UTC](https://community.emergingthreats.net/t/weekly-community-review-june-16-2023/715/1 "2023-07-03T13:26:59Z")

</div>

It’s been a busy #infosec week here at [@et\_labs](https://twitter.com/et_Labs), with exploits, public disclosures, and community contributions across twitter and #Discourse leading to 112 signatures being added to #etopen #suricata and #Snort rulesets. We can chat on a few…

More rules CVE-2023-34362 #MOVEit Transfer application came from writeups, PoC code, and shared research by [@Horizon3ai](https://twitter.com/Horizon3ai) and [@rapid7](https://twitter.com/rapid7), with SIDs 2046188-2046198 modeling observed and documented steps through the exploitation chain. Detection logic for SQL Injection alerting on the setting of session variables, guest account creation, and CSRF token manipulation for API access. (See the SID description file for detailed per-signature breakdowns). Keep in mind - these signatures are based on PoC code and not live captured exploitation traffic.

@kevross33 here on the Discourse provided content as well, and our @bmurphy gave further coverage context and a breakdown of triaging as well: [SIG: MoveIt File Transfer WebShell Interaction](https://community.emergingthreats.net/t/sig-moveit-file-transfer-webshell-interaction/607)

As he says - be mindful of the classtype and severity of received alerts. Major Severity and Classtype “attempted-admin” (SQLi Payload Creation, Guest account creation via SQLi) are higher candidates for triage than Informational serverity “web-application-activity” classtype (API token request, Folder request). While these informational signatures may fire in isolation of other CVE-2023-34362 signatures as part of normal operations, seeing this activity clustered with the higher severity signatures can be indicative of compromise. Be mindful in your triaging and investigations!

Continued great #Gamaredon #APT coverage from [@Cyber0verload](https://twitter.com/Cyber0verload), SIDs 2046213-2046224 on observed domains came from their kind tag!

[twitter.com/Cyber0verload/status/1667482368234381319](http://twitter.com/Cyber0verload/status/1667482368234381319)

This [@welivesecurity](https://twitter.com/welivesecurity) blog (referencing the great [@threatinsight](https://twitter.com/threatinsight) [@Atraggi](https://twitter.com/Atraggi) #AsylumAmbuscade cybercrime group research release) gave us SID 2046247 to alert on outbound install activity.

> **[Asylum Ambuscade: crimeware or cyberespionage?](https://www.welivesecurity.com/2023/06/08/asylum-ambuscade-crimeware-or-cyberespionage/)**
>
> A curious case of a threat actor at the border between crimeware and cyberespionage

From [@SentinelOne](https://twitter.com/SentinelOne), SIDs 2046257-2046260 modeling various methods of #Kimsuky relelated activities around payload retrieval.

[www.sentinelone.com/labs/kimsuky-evolves-reconnaissance-capabilities-in-new-global-campaign/](http://www.sentinelone.com/labs/kimsuky-evolves-reconnaissance-capabilities-in-new-global-campaign/)

Remember, our #Discourse can be a vector for FP reporting as well. Here, user @ksci reports in on a rule that met the wild network landscape and needed some tuning. Our own @trobinson667 responds and the modified rule went out today!

> [@Possible FP: SID 2046267 ET MALWARE \[ANY.RUN\] RisePro TCP v.0.1 (External IP)](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/3):
>
> So far it appears to have only triggered on Team viewer traffic Dest port src port Count 56582 5938 4 50435 443 2 62858 5938 2 12578 443 1 49192 443 1 49680 443 1 49733 443 1 50073 443 1 50135 443 1 50620 443 1 50638 443 1 50817 443 1 50990 443 1 51101 443 1 51334 443 1 51715 5938 1 52366 5938 1 52607 443 1 52778 443 1 53102 443 1 53373 443 1 53796 5938 1 54197 443 1 54588 443 1 54817 443 1 I performed lookups on the source IPs and all …

Concerning CVE-2023-27997 (Fortigate SSL VPN) exploit coverage, this [@LexfoSecurite](https://twitter.com/LexfoSecurite) writeup provided SIDs 2046251-2046256 which alert on repeated POST and GET requests to the hostcheck\_validate and logincheck endpoints - a heap overflow bug provides RCE! These sigs use Threshold to keep FPs down and fire on potential abuse of the endpoints.

[https://blog.lexfo.fr/xortigate-cve-2023-27997.html](https://blog.lexfo.fr/xortigate-cve-2023-27997.html)

Thanks go to [@RexorVc0](https://twitter.com/RexorVc0) for their tweet and [@virustotal](https://twitter.com/virustotal) run enabling SID 2046263 to alerts on a APT-C-36 associated domain lookup from hosts within your networks!

[https://twitter.com/RexorVc0/status/1669016390962118657](https://twitter.com/RexorVc0/status/1669016390962118657)

From @Jane0sint 's Discourse post, SIDs 2042982-2042985,2042987, and 2042989-2042991. Drop by the thread and see the process around laying out their research from which the community benefits!

> [@RisePro TCP v.0.1](https://community.emergingthreats.net/t/risepro-tcp-v-0-1/647/3):
>
> Cool, I also use Dalton! And Risepro v.1.0 in open HTTP is well covered with rules, I used their sids to search for traffic in the database. Another challenge to cover encrypted HTTPS by packet length, it’s a pity this method is not quite suitable for highly loaded systems expressionless So we will use it in the sandbox wink Good luck!

Again here on #Discourse, user @dspruell [@InQuest](https://twitter.com/InQuest) [@Threatlabz](https://twitter.com/Threatlabz) contributes two Mystic Stealer C2 signatures - SIDs 2046293-2046295 are from their great work - check it out!

> [@Mystic Stealer signature](https://community.emergingthreats.net/t/mystic-stealer-signature/658):
>
> Mystic Stealer C2 key exchange. alert tcp $HOME\_NET any -\> $EXTERNAL\_NET any (msg:"ET MALWARE Mystic Stealer C2 Client Hello Packet"; flow:established,to\_server; flowbits:set, mystic\_stealer\_conn\_init; flowbits:noalert; dsize:4; content:"|b5 19 6f 94|"; fast\_pattern; reference:md5,df80b1e50cfebb0c4dbf5ac51c5d7254; reference:url,inquest.net/blog/2023/06/15/mystic-stealer-new-kid-block; reference:url,www.zscaler.com/blogs/security-research/mystic-stealer; classtype:trojan-activity; sid:9999990; r…

Lastly, a large and responsible disclosure from #Barracuda, backed by [@rapid7](https://twitter.com/rapid7) and [@Mandiant](https://twitter.com/Mandiant) reports, has dominated the cybersecurity space this past week. After being alerted to some traffic oddities from their Email Security Gateway appliances investigation found compromised of versions of their Email Security Gateway appliances. A flaw (CVE-2023-2868) exists due to the fact that the Barracuda device does not sanitize the processing of supplied .tar files, particularly around the archive file contents and file names. As such, an attacker can craft file names that will result in the platform executing them with full system privileges. Mandiant’s report identified an actor they track as UNC4841 and kindly provided observed domains post-compromise (SIDs 2046281-2046288) as well as backdoor methods which we were able to model (SIDs 2046273-2046280) all thanks to their comprehensive reporting:

> **[Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by...](https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally)**
>
> Mandiant is investigating a Barracuda ESG appliance zero-day vulnerability being exploited in the wild.

Thanks all - enjoy your weekend. We’ll see you next week.
