Possible GhostContainer Exchange Backdoor C2 Request via OWA (via webserver)

PremiumReviewedSigma · High · v1
Category
webserver
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects HTTP requests to Exchange OWA carrying the custom control header and crafted VIEWSTATE prefix used by the GhostContainer backdoor. GhostContainer is an IIS/Exchange module backdoor deployed against high-value organizations in Asia. Operators tunnel commands through legitimate OWA endpoints which lets malicious traffic blend into normal Exchange usage and evade perimeter controls.

Related detections9 linkedT1071.001 — drag to rearrange
Malicious AdaptixC2 Beacon via X-Beacon-Id Header and Default User Agent (via proxy)
Possible JanelaRAT C2 Beacon via Structured HTTP Query (via proxy)
Suspicious StupidSandwichAgent User-Agent in C2 Traffic by StaryDobry
Suspicious CanesSpy WhatsApp Mod C2 Beacon to AllRequest Endpoint (via proxy)
Suspicious PowerShell WebClient UploadString Network Beacon
Suspicious Command Shell Spawned by MSSQL Server Process Indicating Webshell
Suspicious PipeMagic Named Pipe Creation (via pipe_created)
Suspicious UUID Named Pipe Created Consistent with Mythic SMB Agent
Suspicious RuntimeBroker Network Connection via Loki Mythic Agent
Possible GhostContainer Exchange Backdoor C2 Request via OWA (via webserver)
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.