Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SCAN:CORE:AGENT-LOAD-WIN

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

SCAN

Keywords

Core Agent Load

Release Date

2006/04/26

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SCAN: Core Impact Agent Loading (win32)


This signature detects the transfer and first loading of a Core Impact Agent over the network. This agent provides the attacker with full control over the victim computer. Detecting this transfer indicates that a successful exploitation is going on, which must be stopped immediately to mitigate the consequences.

Extended Description

The CORE IMPACT agent can be used to execute arbitrary shell commands on a compromised Windows system. The agent may obtain additional Windows APIs as binary plug-ins providing additional functionality to compromise other systems or disrupt network operations.

References

  • URL: http://www.coresecurity.com/products/coreimpact/index.php

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out