Removed rule. This rule is known, but it is no longer present in its source. Showing the last known version.Removed: Jul 5, 2026, 4:07 AM
THL CVE-2026-41940 Operator Flask C2 Dashboard - Werkzeug/3.1.8 Banner with /login-2fa Redirect
Sourcehunters-ledger
Filehunters-ledger.rules
CreatedJune 25, 2026
UpdatedJune 25, 2026
Classificationtrojan-activity
alert http any any -> any any (msg:"THL CVE-2026-41940 Operator Flask C2 Dashboard - Werkzeug/3.1.8 Banner with /login-2fa Redirect"; flow:established,to_client ; http.server; content:"Werkzeug/3.1.8 Python/3.13.12"; endswith; nocase; http.header; content:"Location|3a 20|/login-2fa"; nocase; reference:url,the-hunters-ledger.com/reports/opendirectory-216-126-227-49-cve-2026-41940-cpanel-harvester-20260517/ ; classtype:trojan-activity; sid:1900050; rev:1;)
References
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!