← All detection heuristics · Shellcode
critical
SC_MSF_REVERSE
What it means
Byte signature matching Metasploit Framework reverse_tcp shellcode.
Why it fires
This exact byte sequence is the preamble of Metasploit's reverse TCP shell payload — one of the most widely-used exploitation tools. Its presence is consistent with a weaponised file.
Other Shellcode heuristics
SC_STR_CREATEREMOTETHREAD SC_MSF_BIND SC_MSF_C2 SC_STR_URLDOWNLOAD SC_STR_WRITEPROCESSMEMORY SC_XOR_ENCODED SC_STR_CREATEPROCESS SC_EGG_HUNTER SC_STR_GETPROCADDRESS SC_HEAP_SPRAY SC_STR_LOADLIBRARY SC_API_HASH_RESOLVER SC_PEB_ACCESS_X64 SC_PEB_ACCESS SC_STR_POWERSHELL SC_STR_SHELLEXEC SC_STR_WINEXEC SC_STR_WSCRIPT SC_XOR_DECODER SC_XOR_DECODED_NETWORK_CONFIG SC_STR_BITSADMIN SC_STR_CERTUTIL SC_STR_CMD SC_STR_MSHTA