Removed rule. This rule is known, but it is no longer present in its source. Showing the last known version.Removed: Jul 5, 2026, 4:07 AM

THL HijackLoader Staging Server 109.120.137.6 PUTTY.exe Payload Download

SID: 1900059Rev: 1Enabled2 viewsHistory
Filehunters-ledger.rules
CreatedMay 6, 2026
UpdatedMay 6, 2026
Classificationtrojan-activity
alert http $HOME_NET any -> 109.120.137.6 any (msg:"THL HijackLoader Staging Server 109.120.137.6 PUTTY.exe Payload Download"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/PUTTY.exe"; nocase; classtype:trojan-activity; sid:1900059; rev:1; metadata:affected_products Windows, attack_target Client_Endpoint, created_at 2026_05_06, deployment Perimeter, former_category MALWARE, malware_family HijackLoader, mitre_tactic_id TA0011, mitre_technique_id T1105, performance_impact Low, signature_severity Major, updated_at 2026_05_06; reference:url,the-hunters-ledger.com/hunting-detections/opendirectory-62-60-237-100-20260506-detections/;)

Metadata

affected productsWindows
attack targetClient_Endpoint
created at2026_05_06
deploymentPerimeter
former categoryMALWARE
malware familyHijackLoader
mitre tactic idTA0011
mitre technique idT1105
performance impactLow
signature severityMajor
updated at2026_05_06

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!