SHELLCODE: Prepend Encoder Routine Detection Over HTTP

This signature detects payloads being transferred over network that use the PrependEncoder routine. This may be an indication of someone trying to drop malicious file content on targeted systems to achieve remote code execution.

Short Name
SHELLCODE:PREPENDENCODER-HTTP
Severity
Major
Recommended
False
Recommended Action
None
Category
SHELLCODE
Keywords
Detection Encoder HTTP Over Prepend Routine
Release Date
08/19/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?