""ET SHELLCODE Execve(/bin/sh) Shellcode""

SID: 2025695

Revision: 1

Class Type: shellcode-detect

Metadata: affected_product Linux, attack_target Server, created_at 2018_07_13, deployment Perimeter, performance_impact Low, updated_at 2018_07_13

Reference:

Protocol: ip

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: any

Flow:

Contents:

  • Value: "|31 c0 50 68 2f 2f 73 68 68 2f 62 69 6e 89 e3 50 53 89 e1 b0 0b cd 80|"

Within:

PCRE:

Special Options:

source