Short Name |
SHELLCODE:WIN:SMB-REM-EXEC1 |
---|---|
Severity |
Medium |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
SHELLCODE |
Keywords |
Remote Execute Command (Little Endian) |
Release Date |
2013/07/10 |
Update Number |
2280 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects Windows x86 shellcode that executes remote commands on a victim's system, such as launch calc.exe or perform a message pop-up. This is most likely an indication of attack.