Removed rule. This rule is known, but it is no longer present in its source. Showing the last known version.Removed: Jul 5, 2026, 4:07 AM

THL CVE-2026-41940 Operator Flask C2 Dashboard - Werkzeug/3.1.8 Banner with /login-2fa Redirect

SID: 1900050Rev: 1Enabled5 viewsHistory
Filehunters-ledger.rules
CreatedJune 25, 2026
UpdatedJune 25, 2026
Classificationtrojan-activity
alert http any any -> any any (msg:"THL CVE-2026-41940 Operator Flask C2 Dashboard - Werkzeug/3.1.8 Banner with /login-2fa Redirect"; flow:established,to_client; http.server; content:"Werkzeug/3.1.8 Python/3.13.12"; endswith; nocase; http.header; content:"Location|3a 20|/login-2fa"; nocase; reference:url,the-hunters-ledger.com/reports/opendirectory-216-126-227-49-cve-2026-41940-cpanel-harvester-20260517/; classtype:trojan-activity; sid:1900050; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!