SHELLCODE: Solaris write and exit System Calls

This signature detects shellcode designed to execute write and exit system call on Solaris platforms. Although, not suspicious on their own, but when these system calls are found in a particular sequence, it could be an indication of malicious activity within your network.

Short Name
SHELLCODE:SPARC:WRITE-EXIT
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
SHELLCODE
Keywords
Calls Solaris System and exit write
Release Date
05/08/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/1-79,81-442,444-3127,3129-7999,8001-8079,8081-65535
False Positive
Unknown

Found a potential security threat?