# Weekly Community Review - October 18, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-october-18-2023/1057>\
**Category:** Announcements\
**Created:** [October 20, 2023, 1:54am UTC](https://community.emergingthreats.net/t/weekly-community-review-october-18-2023/1057 "2023-10-20T01:54:25Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [October 20, 2023, 1:54am UTC](https://community.emergingthreats.net/t/weekly-community-review-october-18-2023/1057/1 "2023-10-20T01:54:25Z")

</div>

Greetings all! Last week here at ET was a good one - thanks to public sharing, intel disclosures, wonderful research, and rule submissions we all added 75 rules to our ET Open ruleset - including rules covering #CVE-2023-22515, the critical #Confluence zero-day!

The #community aspect of infosec is important to us. In fact, it’s what powers #etopen and allows us to offer those rules up for free here: [Proofpoint Emerging Threats Rules](https://rules.emergingthreatspro.com/open/)

So you can find those rules there! You can find them in your marked in your suricata.yaml upon install and you can config your instance to grab what you like. You can use suricata-update keep current. They’re meant to protect your monitored networks. All we ask is you give us some feedback!

> **[Feedback & Support](https://community.emergingthreats.net/c/feedback-support/8)**
>
> Unofficial Support and Feedback for ET products.

Digging into those 75 - from this @[akami](https://twitter.com/akamai) blog we’ve got a #MageCart detection - SID 2048531 alerts on the identified “COOKIE\_ANNOT” text string appearing within the returned HTML!

> **[The Art of Concealment: A New Magecart Campaign That’s Abusing 404 Pages |...](https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer)**
>
> Akamai researchers have discovered a novel obfuscation technique that Magecart attackers are using to hide malicious code and infiltrate websites.

This @[ptsecurity](https://twitter.com/ptsecurity) #DarkRiver #Matador writeup helped us (with a lot of @greg genius too!) write SID 2048550 alerting on a consistent byte payload indicating C2 beacon activity!

> **[Dark River. You can't see them, but they're there](https://ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/dark-river-you-can-t-see-them-but-they-re-there/)**
>
> Dark River. You can't see them, but they're there

Here on our #Discourse site, just a ton of great information sharing. In this #Darkgate #Stealer thread, our friend @Jane0sint tees up the research and analysis that ends in proposed detection logic - and this becomes SID 2048558! Read this thread. You Will Learn!

> [@DarkGate](https://community.emergingthreats.net/t/darkgate/1033):
>
> Hi, having decrypted and detonated this sample that was received at the first stage of delivery, I noticed some features of http that can be used for detection. For example, the same user agent, lifetime and what is interesting is the use of a capital letter in the content description: I did not hardcode the port since there is also a request for 8080. The body of the request now looks slightly different due to the use of substitution encryption and I always had 102 bytes, the firs…

And speaking of learning - check out our Tutorials, Tips, & Tricks section. In this thread, ET’s @jtaylor talks about #suricata’s prefilter keyword. You can potentially fast\_pattern when you don’t think you can fast\_pattern.

> [@Prefilter Keyword Usage and Signature Performance](https://community.emergingthreats.net/t/prefilter-keyword-usage-and-signature-performance/1035):
>
> The prefilter keyword allows Suricata to use keywords that are not part of the multi-pattern-matcher detection engine as fast\_patterns. (prefilter reference: [8.10. Prefiltering Keywords — Suricata 7.0.2-dev documentation](https://docs.suricata.io/en/latest/rules/prefilter-keywords.html#prefilter)) The MPM detection engine is what looks at the fast\_pattern content of a signature to determine if the signature is evaluated further. (MPM reference: [12.1. Suricata.yaml — Suricata 7.0.2-dev documentation](https://docs.suricata.io/en/latest/configuration/suricata-yaml.html#pattern-matcher-settings)) The current version of suricata.yaml has the following default setting…

I mentioned earlier the #Atlassian #Confluence #CVE-2023-22515. Vulnerable versions of Confludence Data Center can be remotely exploited to allow administrator accounts. This is full unauthenticated “zero to hero” capability exploited in the wild. Privileged access is granted when executed against a publicly available endpoint.

[https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-289a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-289a)

As documented in this #CISA #Cybersecurity advisory, our released signatures are recommended as a detection method of exploitation for #CVE-2023-22515. These are 2048469-2048470 to identify scanning reconaissance against your potentially vulnerable instance, 2048543 and 2048546 firing on the detection of a vulnerable server, and 2048541-2048542 & 2048544-2048545 alerting on explolitation success.

Lastly, we’re very proud of our own @dumiller and his #FakeBrowser update lure blog featuring points on #socgholish #TA569 #RogueRaticate #ZPHP #ClearFake - plenty to learn, and referenced #etopen signatures as well!

> **[Are You Sure Your Browser is Up to Date? The Current Landscape of Fake...](https://www.proofpoint.com/us/blog/threat-insight/are-you-sure-your-browser-date-current-landscape-fake-browser-updates)**
>
> Key Takeaways 

Take care all!
