HTTP: Suspicious Portable Executable File Download Attempt

This signature detects an attempt to download an obfuscated Portable Executable file from any target web server. Successful exploitation could allow an attacker to execute arbitrary codes into the context of the target running operating system.

Short Name
HTTP:STC:DL:OBF-PE-DL
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Attempt Download Executable File Portable Suspicious
Release Date
06/09/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?