Short Name |
SHELLCODE:X86:GETEIP-XOR-CTS |
---|---|
Severity |
Critical |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
SHELLCODE |
Keywords |
X86 OS agnostic Call geteip Byte XOR Decoder Routine Over TCP-CTS |
Release Date |
2015/08/17 |
Update Number |
2526 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects payloads being transferred over network that have been encoded using x86 call geteip byte xor decoder routine. This may be an indication of someone trying to evade anti-virus/IPS solutions and possibly drop malicious code.