SCAN: Core Impact Agent Loading (win32)
This signature detects the transfer and first loading of a Core Impact Agent over the network. This agent provides the attacker with full control over the victim computer. Detecting this transfer indicates that a successful exploitation is going on, which must be stopped immediately to mitigate the consequences.
Extended Description
The CORE IMPACT agent can be used to execute arbitrary shell commands on a compromised Windows system. The agent may obtain additional Windows APIs as binary plug-ins providing additional functionality to compromise other systems or disrupt network operations.
References
URL: http://www.coresecurity.com/products/coreimpact/index.php
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3