THL HUNT WebLogicTelecomHarvester Cisco IOS-XE Double-Encoded WSMA Path Bypass (CVE-2023-20273 Operator Fingerprint)
Sourcehunters-ledger
Filehunters-ledger.rules
CreatedSeptember 2, 2026
UpdatedSeptember 2, 2026
Classificationtrojan-activity
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"THL HUNT WebLogicTelecomHarvester Cisco IOS-XE Double-Encoded WSMA Path Bypass (CVE-2023-20273 Operator Fingerprint)"; flow:established,to_server ; content:"%2577eb%2575i_%2577sma_Http"; http_uri; threshold:type limit,track by_src,count 1,seconds 3600 ; classtype:trojan-activity; sid:3500188; rev:1; metadata:author The_Hunters_Ledger, date 2026-08-17, reference https://the-hunters-ledger.com/hunting-detections/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817-detections/ ;)
Metadata
authorThe_Hunters_Ledger
date2026-08-17
referencehttps://the-hunters-ledger.com/hunting-detections/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817-detections/
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!