SHELLCODE: Prepend Encoder Routine Detection Over HTTP (1)

This signature detects payloads being transferred over network that use the PrependEncoder routine. This may be an indication of someone trying to drop malicious file content on targeted systems to achieve remote code execution.

Short Name
SHELLCODE:PREPENDENCODER-HTTP-1
Severity
Major
Recommended
True
Recommended Action
None
Category
SHELLCODE
Keywords
(1) Detection Encoder HTTP Over Prepend Routine
Release Date
09/08/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?