# Weekly Community Review - September 21, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-september-21-2023/977>\
**Category:** Announcements\
**Created:** [September 22, 2023, 1:21am UTC](https://community.emergingthreats.net/t/weekly-community-review-september-21-2023/977 "2023-09-22T01:21:46Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [September 22, 2023, 1:21am UTC](https://community.emergingthreats.net/t/weekly-community-review-september-21-2023/977/1 "2023-09-22T01:21:46Z")

</div>

Greetings all! We had a great week of research and community collaboration last week - over 100 (109!) rules were added to our free #etopen ruleset thanks to these efforts, and we wanted to spend some time going over how we were helped and what came from that sharing.

Thanks for @[tiresearch1](https://twitter.com/tiresearch1) and our own @[greglesnewich](https://twitter.com/greglesnewich) for the sharing and intel tip-up that became DNS and TLS SNI SIDs 2047995-2048032!

> <https://twitter.com/tiresearch1/status/1701155845608964391>

That’s a lot of intel and it translates into a lot of sigs and potentially a lot of alerts! To what end? We’ve talked about DNS query alerts before - these fires can indicate hosts within your visibility are making queries for domains for purposes that may be malicious - but they’re not a silver bullet for infection. They should be correlated with other activities and alerts and are the beginning of a DFIR investigation–not the end.

So why do we write sigs like that? Well sometimes it’s because some of the more involved traffic is encrypted–and that’s hard for us to dig-in to. In this post, ET’s own Brandon Murphy talks about our challenges with IOC-based rules and TLS encryption - within you’ll see what our options are and why we make some of the detection logic and naming choices we do:

> [@Handling IOC Based Rules with TLS Decryption](https://community.emergingthreats.net/t/handling-ioc-based-rules-with-tls-decryption/948):
>
> A customer recently requested details on how Emerging Threats ensures coverage of rules which leverage TLS keywords for environments which have TLS decryption in place. This specific environment involves the TLS decryption process removing the TLS Protocol and presenting plain text HTTP to the IDS Engine. A great question that I figured was worth sharing with everyone! In general, Emerging Threats attempts to write signatures which provide coverage regardless if an environment has TLS decrypti…

Friend @Jane0sint provides some bytes and siggable args along with some @[virustotal](https://twitter.com/virustotal) intel which guided us to SID 2048043 - alerting on Chifrax.a exfil to a C2:

> <https://twitter.com/Jane_0sint/status/1701545803741905182>
>
> Jane @Jane\_0sint

Here on our Discourse, user @j0hnb3r00t shares an updated #ScreenConnect checkin packet byte pattern via a linked @anyrun analysis - this became SID 2048051 - another method to alert on ScreenConnect-ConnectWise activity which may be against policy within your environs:

> [@Update/new rule needed for ScreenConnect? sid:2036627](https://community.emergingthreats.net/t/update-new-rule-needed-for-screenconnect-sid-2036627/938):
>
> Hello, While I was following a campaign using ScreenConnect maliciously, I noticed that the initial checkin packet may have changed. As can be seen in the screenshot below, it looks like it is now “87 1C 10” instead of “87 15 10”. Here is the link to this specific any.run analysis: [Analysis hgsuhfs.exe (MD5: A047BFE20C52C21BC6060FF0F763C235) Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/74030a66-0d50-4d2d-ae95-17489b5fabcf/) Regards, John

We say policy there distinctly - those rule fires may mean everything to you, or nothing at all. They category exists for filtering like that! It’s distinctly for signatures that may indicate violations to an organization’s policy. This can include protocols prone to abuse and other application-level transactions which may be of interest.

From @[twinwavesec](https://twitter.com/twinwavesec) friendly sharing, SIDs 2048044-2048048, all observed phishing domain alerts - be on the lookout!

From @Jane0sint on our #Discourse, referencing up a @James_inthe_box tweet on #darkcrystal #rat they submit a rule referencing the observed byte patterns in network traffic for the check-in. Off to #etopen which becomes SID 2048095!

> [@DarkCrystal RAT](https://community.emergingthreats.net/t/darkcrystal-rat/952):
>
> Hello again! Our good friend James found DCrat malware traffic with a new encryption layer In turn, I quickly compared the first 344 byte check-ins and received static bytes. Probably the rule will be further clarified, I’m working on deciphering it. But for now I dare to propose the following solution alert http any any -\> any any (msg: "ET MALWARE [ANY.RUN] DarkCrystal Rat Check-in";flow: established, to\_server; http.method; content: "POST"; http.header; content: "Content-Lengt…

Great sigs off industry intel shares last week as well! From @[symantec](https://twitter.com/symantec), SID 2048088 for referenced #ShadowPad #Trojan #C2 domain lookup:

> **[Redfly: Espionage Actors Continue to Target Critical Infrastructure](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/critical-infrastructure-attacks)**
>
> National grid in Asia compromised by attackers using ShadowPad Trojan.

And from @[TrendMicro](https://twitter.com/TrendMicro), SIDs 2048084-2048086 with a wonderful writeup full of analysis & guidance by ET’s @trobinson667 :

> [@Android/MMRAT : Additional Analysis](https://community.emergingthreats.net/t/android-mmrat-additional-analysis/943):
>
> Hello! Today, I wanted to talk about the Android MMRAT Banking Trojan. This trojan has a ton of features and was covered very well by a recent Trend Micro blog post here: and for those of you wanting IOCs, they posted those here: [https://www.trendmicro.com/content/dam/trendmicro/global/en/research/23/h/mmrat-carries-out-bank-fraud-via-fake-app-stores/IOC\_stealthy-android-malware-mmrat-carries-out-bank-fraud-via-fake-app-stores.txt](https://www.trendmicro.com/content/dam/trendmicro/global/en/research/23/h/mmrat-carries-out-bank-fraud-via-fake-app-stores/IOC_stealthy-android-malware-mmrat-carries-out-bank-fraud-via-fake-app-stores.txt) I used this information, a long with some PCAPs I scored to…
