# Weekly Community Review - November 2, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-november-2-2023/1260>\
**Category:** Announcements\
**Created:** [November 2, 2023, 5:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-november-2-2023/1260 "2023-11-02T05:00:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [November 2, 2023, 5:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-november-2-2023/1260/1 "2023-11-02T05:00:00Z")

</div>

Greetings all! We’re here to talk about a few sigs from last week’s batch. Thanks to some great contributions to our #infosec community we were able to add 207 (!) rules into our free #suricata and snort offerings as part of ETOpen.

> [@Frequently Asked Questions](https://community.emergingthreats.net/t/frequently-asked-questions/56):
>
> What is Emerging Threats? Emerging Threats is a division of Proofpoint, Inc. Our primary projects are the Emerging Threats Ruleset, contributed and maintained by the security community, and the Emerging Threats Pro Ruleset, which is maintained by the Proofpoint/ET research team, as well as the Emerging Threats Intelligence Product. Are the Emerging Threats (Open) Rules REALLY free? Yup. Free, as in BSD licensed, which allows you to do what you like with them. All we ask is that when you have an…

Over 200 free detections went out into ETOpen this week - and the bulk of those are from the great work of our friend @[infosectimmy](https://twitter.com/infosectimmy) and his battle against TOAD (Telephone-Oriented Attack Delivery). Tim bats #toad actors around like a cat and its ball of yarn! Read more here:

> **[The 411 on Call Center Scams & Fraud | Proofpoint US](https://www.proofpoint.com/us/blog/threat-insight/caught-beneath-landline-411-telephone-oriented-attack-delivery)**
>
> Call center scams are attempted tens of thousands of times daily. Proofpoint shares the role of call center threats in a sophisticated series of cyber attacks.

We had other help too! Here, @[naumovax](https://twitter.com/naumovax) posts kind sandbox runs we used to sig an exfiltration method for PovertyStealer. SID 2048736 is born!

> <https://twitter.com/naumovax/status/1716452167538577741>

From friend @[suyog41](https://twitter.com/suyog41), hashes for NewsRAT allowing us to alert on an inbound C2 response in SID 2048924:

> <https://twitter.com/suyog41/status/1717789648590918134>
>
> Yogesh Londhe @suyog41

The ETOpen ruleset is built upon community sharing. Intel, tips, pcaps, sandbox runs, or direct sig submissions help us put those these free protections for your use - for everyone’s use! Get in touch with us at support(at)emergingthreats(dot)net, [feedback.emergingthreats.net](http://feedback.emergingthreats.net), or at our #Discourse site!

[https://community.emergingthreats.net/](https://community.emergingthreats.net/)

You’re here, so heck out this thread! @Jane0sint @James_inthe_box @ [Racco42](https://twitter.com/Racco42/status/1716498733183926306) collective work becomes SIDs 2048900-2048902 covering two #PureLogs connection methods and an exfiltration attempt - follow the thrad, check out the bytes, and see how those sigs were worked out!

> [@PureLogs Stealer](https://community.emergingthreats.net/t/purelogs-stealer/1059/6):
>
> Thanks for your response. Check, rule doesn’t work here, otherwise we may encounter 126 byte packet like here. Regarding the content mismatch check, I use negation so that I don’t encounter a null sequence before 40 00 00 00 and accidentally trigger it. byte\_extract: 8, -68, bytes0, relative; byte\_test: 8, =, bytes0, -80, relative; byte\_test: 8, !=, bytes0, -81, relative; It is noticed that such a packet with these bytes (40 00 00 00) is exfiltrated twice in one stream. And …

Last wrap-up thread we talked about the new @[nsacyber](https://twitter.com/nsacyber) ELITEWOLF signatures added to open - in this post, ET’s @trobinson667 talks about his analysis process and the trials and tribulations of alert intake!

> [@nsacyber/ELITEWOLF rules - Now in ETOPEN](https://community.emergingthreats.net/t/nsacyber-elitewolf-rules-now-in-etopen/1066):
>
> Hey folks, If you’re not aware, NSACyber made a github repo that they’re calling [ELITEWOLF](https://github.com/nsacyber/ELITEWOLF) To make a long story short, it is a collection of rules that are meant to detect activity involving ICS Controllers from a variety of vendors – SSH login attempts, Browsing to the embedded web server on a controller, TELNET and FTP Banners, Default Credentials, Default SSL certificates, viewing certain pages that could contain sensitive information about the controller’s configuration, etc. While most of…

We’ve worked hard on CVE-2023-20198 last week and continued to do so - many thanks to those that’ve shared their observations, experiences, & analysis to help make our protections better, including @[foxit](https://twitter.com/foxit), @[greynoiseIO](https://twitter.com/greynoiseIO), @[SI\_FalconTeam](https://twitter.com/SI_FalconTeam) , and @[Horizon3ai](https://twitter.com/Horizon3ai)!

> [@Ruleset Update Summary - 2023/10/30 - v10452](https://community.emergingthreats.net/t/ruleset-update-summary-2023-10-30-v10452/1080):
>
> Summary: 68 new OPEN, 69 new PRO (68 + 1) Thanks @SI\_FalconTeam, @Horizon3ai, @ginkgo\_g Added rules: Open: 2048933 - ET MALWARE Suspected Bumblebee Loader Activity (malware.rules) 2048934 - ET INFO Cisco IOS XE Web Server Auth From Suspicious Username (cisco\_support) (CVE-2023-20198) (Inbound) (info.rules) 2048935 - ET HUNTING Cisco IOS XE Web Server Auth From Suspicious Username (cisco\_support) (CVE-2023-20198) (Outbound) (hunting.rules) 2048936 - ET HUNTING Suspicious Cisco Privilege Level…

From other industry sharing - two SIDs on Golang EasyStealer POST methods (2048896-2048897) went out past and available byte patterns identified from this @[bridewellsec](https://twitter.com/bridewellsec) post:

> **[Uncovering the “Easy Stealer” Infostealer](https://www.bridewell.com/insights/blogs/detail/uncovering-the-easy-stealer-infostealer)**
>
> Uncovering the “Easy Stealer” Infostealer

And from our @[CISAgov](https://twitter.com/CISAgov) friends, identification of a VoltTyphoon user agent is the alerting in SID 2048899 thanks for their sharing in this write of the PRC state-sponsored actor:

[https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA\_PRC\_State\_Sponsored\_Cyber\_Living\_off\_the\_Land\_v1.1.PDF](https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_PRC_State_Sponsored_Cyber_Living_off_the_Land_v1.1.PDF)

Listen to ET’s own @dumiller on the @[threatinsight](https://twitter.com/threatinsight)  
DISCARDED podcast - Dusty talks about SocGholish, RogueRaticate, SmartApeSG, and ClearFake covering the world of Fake Browser updates and the sigs he’s written to protect us all:

> **[Unmasking the Tricksters: The World of Fake Browser Updates](https://www.spreaker.com/episode/unmasking-the-tricksters-the-world-of-fake-browser-updates--57445354)**
>
> How can you tell when a website (yes, a website) is compromised? These threats are pretty crafty because they aren't out to target specific individuals; they ju

That’s it for us and last week’s additions - take care and be well!
