Removed rule. This rule is known, but it is no longer present in its source. Showing the last known version.Removed: Jul 5, 2026, 4:07 AM
THL - Covenant GruntStager C2 Beacon - Campaign Session Token in HTTP POST
Sourcehunters-ledger
Filehunters-ledger.rules
CreatedApril 3, 2026
UpdatedApril 3, 2026
Classificationtrojan-activity
alert http $HOME_NET any -> $EXTERNAL_NET 443 (msg:"THL - Covenant GruntStager C2 Beacon - Campaign Session Token in HTTP POST"; flow:established,to_server ; http.method; content:"POST"; http.uri; content:"/en-us/"; startswith; http.request_body; content:"session=75db-99b1-25fe4e9afbe58696-320bea73"; classtype:trojan-activity; reference:url,pixelatedcontinuum.github.io/Threat-Intel-Reports/hunting-detections/opendirectory-193-56-255-154-20260403-detections/ ; sid:1900044; rev:1; metadata:affected_product Windows, attack_target Client_Endpoint, created_at 2026_04_03, deployment Perimeter, malware_family Covenant, signature_severity Major, tag C2;)
Metadata
affected productWindows
attack targetClient_Endpoint
created at2026_04_03
deploymentPerimeter
malware familyCovenant
signature severityMajor
tagC2
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!