x86 GetPC stub (CALL $+5)

SC_GETPC_CALL

← All detection heuristics · Shellcode

info SC_GETPC_CALL

What it means

x86 CALL $+5 instruction sequence that obtains the current instruction pointer.

Why it fires

Shellcode needs to know its own memory address to locate encoded payloads. CALL $+5 followed by POP is a common way to get the program counter (PC). This pattern is unusual in normal documents.

Other Shellcode heuristics

SC_STR_CREATEREMOTETHREAD SC_MSF_BIND SC_MSF_REVERSE SC_MSF_C2 SC_STR_URLDOWNLOAD SC_STR_WRITEPROCESSMEMORY SC_XOR_ENCODED SC_STR_CREATEPROCESS SC_EGG_HUNTER SC_STR_GETPROCADDRESS SC_HEAP_SPRAY SC_STR_LOADLIBRARY SC_API_HASH_RESOLVER SC_PEB_ACCESS_X64 SC_PEB_ACCESS SC_STR_POWERSHELL SC_STR_SHELLEXEC SC_STR_WINEXEC SC_STR_WSCRIPT SC_XOR_DECODER SC_XOR_DECODED_NETWORK_CONFIG SC_STR_BITSADMIN SC_STR_CERTUTIL SC_STR_CMD