SCAN: Metasploit Meterpreter DLL

This signature detects the Metasploit Framework meterpreter DLL being transferred from one system to another. This is generally an indication that a destination system was successfully exploited by a source system. Both hosts can be compromised and should be investigated.

Extended Description

The use of DLL extensions in a Meterpreter allows attackers to execute desired commands or code on the compromised system. The attacker may also cause network operation disruption or denial of service condition via the compromised host in a network.

Short Name
SCAN:METASPLOIT:METERPRETER-DLL
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
SCAN
Keywords
DLL Metasploit Meterpreter
Release Date
08/17/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/4444
False Positive
Unknown

Found a potential security threat?