SHELLCODE: X86 OS agnostic Call geteip Byte XOR Decoder Routine Over HTTP-CTS

This signature detects payloads being transferred over network that have been encoded using x86 call geteip byte xor decoder routine. This may be an indication of someone trying to evade anti-virus/IPS solutions and possibly drop malicious code.

Short Name
SHELLCODE:X86:GETEIP-XOR-80C
Severity
Critical
Recommended
True
Recommended Action
Drop
Category
SHELLCODE
Keywords
Byte Call Decoder HTTP-CTS OS Over Routine X86 XOR agnostic geteip
Release Date
08/17/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?