Skip to content

Files

Latest commit

 

History

History
39 lines (39 loc) · 13.9 KB

PastebinLike_tag_detection.csv

File metadata and controls

39 lines (39 loc) · 13.9 KB
1
keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_at
2
* | clbin*.{0,1000}\s\|\sclbin.{0,1000}greyware_tool_keywordclbin.comclbin.com be used for C&C purposes. The attacker will place commands on a textbin paste and have the malware fetch the commands.T1567.002TA0010 - TA0009N/AN/AData Exfiltrationhttps://clbin.com/10#PastebinLikeN/A88N/AN/AN/AN/A
3
* nc termbin.com *.{0,1000}\snc\stermbin\.com\s.{0,1000}greyware_tool_keywordtermbin.comsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationtermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A
4
* netcat termbin.com *.{0,1000}\snetcat\stermbin\.com\s.{0,1000}greyware_tool_keywordtermbin.comsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationtermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A
5
* termbin.com 9999*.{0,1000}\stermbin\.com\s9999.{0,1000}greyware_tool_keywordtermbin.comsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationtermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A
6
*0bin - encrypted pastebin*.{0,1000}0bin\s\-\sencrypted\spastebin.{0,1000}greyware_tool_keyword0bin.netAccessing a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/ACollectionhttps://0bin.net10#PastebinLikeN/A510N/AN/AN/AN/A
7
*A client side encrypted PasteBin*.{0,1000}A\sclient\sside\sencrypted\sPasteBin.{0,1000}greyware_tool_keyword0bin.netAccessing a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/ACollectionhttps://0bin.net10#content #PastebinLikeN/A510N/AN/AN/AN/A
8
*curl https://termbin.com/*.{0,1000}curl\shttps\:\/\/termbin\.com\/.{0,1000}greyware_tool_keywordtermbin.comaccessing paste raw contentT1119TA0009N/AN/ACollectiontermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A
9
*curl*nopaste.net*.{0,1000}curl.{0,1000}nopaste\.net.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingservice #linuxN/A810N/AN/AN/AN/A
10
*docker run */.config/pcopy*.{0,1000}docker\srun\s.{0,1000}\/\.config\/pcopy.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingservice #linuxN/A810N/AN/AN/AN/A
11
*http://pastie.org/p/*/raw*.{0,1000}http\:\/\/pastie\.org\/p\/.{0,1000}\/raw.{0,1000}greyware_tool_keywordpastie.orgaccessing paste raw contentT1119TA0009N/AN/ACollectionhttp://pastie.org/11#PastebinLikeN/A88N/AN/AN/AN/A
12
*http://pastie.org/pastes/create*.{0,1000}http\:\/\/pastie\.org\/pastes\/create.{0,1000}greyware_tool_keywordpastie.orgsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationhttp://pastie.org/11#PastebinLikeN/A88N/AN/AN/AN/A
13
*http://zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd.onion*.{0,1000}http\:\/\/zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd\.onion.{0,1000}greyware_tool_keywordzerobin.netaccessing paste raw contentT1119TA0009N/AN/ACollectionhttps://zerobin.net/11#PastebinLikeN/A88N/AN/AN/AN/A
14
*https://0bin.net/paste/*+*.{0,1000}https\:\/\/0bin\.net\/paste\/.{0,1000}\+.{0,1000}greyware_tool_keyword0bin.netAccessing a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/ACollectionhttps://0bin.net11#PastebinLikeN/A510N/AN/AN/AN/A
15
*https://0bin.net/paste/create*.{0,1000}https\:\/\/0bin\.net\/paste\/create.{0,1000}greyware_tool_keyword0bin.netCreating a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://0bin.net11#PastebinLikeN/A910N/AN/AN/AN/A
16
*https://1ty.me/*.{0,1000}https\:\/\/1ty\.me\/.{0,1000}greyware_tool_keyword1ty.metemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AN/ACollectionhttps://1ty.me11#PastebinLikedownloading or uploading data1010N/AN/AN/AN/A
17
*https://1ty.me/?mode=ajax&cmd=create_note*.{0,1000}https\:\/\/1ty\.me\/\?mode\=ajax\&cmd\=create_note.{0,1000}greyware_tool_keyword1ty.metemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AN/AData Exfiltrationhttps://1ty.me11#PastebinLikecreating note1010N/AN/AN/AN/A
18
*https://apaste.info/p/new*.{0,1000}https\:\/\/apaste\.info\/p\/new.{0,1000}greyware_tool_keywordapaste.infoCreating a paste on apaste.info/T1213 - T1190TA0001 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://apaste.info/11#PastebinLikeN/A910N/AN/AN/AN/A
19
*https://clbin.com/*.{0,1000}https\:\/\/clbin\.com\/.{0,1000}greyware_tool_keywordclbin.comclbin.com be used for C&C purposes. The attacker will place commands on a textbin paste and have the malware fetch the commands.T1567.002TA0010 - TA0009N/AN/AData Exfiltrationhttps://clbin.com/11#PastebinLikeN/A88N/AN/AN/AN/A
20
*https://nopaste.net/*.{0,1000}https\:\/\/nopaste\.net\/.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://www.shellhub.io/11#Pastebinlike #filehostingservicemonitor PUT requests for data exfiltration810N/AN/AN/AN/A
21
*https://privatebin.net/*.{0,1000}https\:\/\/privatebin\.net\/.{0,1000}greyware_tool_keywordprivatebin.netInteresting observation on the file-sharing platform preferences derived from the negotiations chats with Black Basta victimsT1071.001 - T1567.002 - T1005TA0010 - TA0009N/ABlack BastaData ExfiltrationN/A01#PastebinLikeN/A56N/AN/AN/AN/A
22
*https://privnote.com/*.{0,1000}https\:\/\/privnote\.com\/.{0,1000}greyware_tool_keywordprivnote.comtemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAkira - Black BastaCollectionhttps://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Akira/20240620.json#L31C27-L31C4811#PastebinLikedownloading files url55482502025-01-24T16:38:39Z2023-05-02T16:17:48Z
23
*https://rentry.co/*.{0,1000}https\:\/\/rentry\.co\/.{0,1000}greyware_tool_keywordrentry.coaccessing a pastebinlike site - often abused by malwareT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A58N/AN/AN/AN/A
24
*https://rentry.co/*/raw*.{0,1000}https\:\/\/rentry\.co\/.{0,1000}\/raw.{0,1000}greyware_tool_keywordrentry.coraw format paste access attempt - abused by attackers to store malicious payloadsT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A78N/AN/AN/AN/A
25
*https://rentry.co/cdn-cgi/challenge-platform/*.{0,1000}https\:\/\/rentry\.co\/cdn\-cgi\/challenge\-platform\/.{0,1000}greyware_tool_keywordrentry.coraw format paste access attempt - abused by attackers to store malicious payloadsT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A78N/AN/AN/AN/A
26
*https://textbin.net/raw/*.{0,1000}https\:\/\/textbin\.net\/raw\/.{0,1000}greyware_tool_keywordtextbin.nettextbin.net raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectiontextbin.net11#PastebinLikegreyware tool - risks of False positive !1010N/AN/AN/AN/A
27
*https://zerobin.net/?*.{0,1000}https\:\/\/zerobin\.net\/\?.{0,1000}greyware_tool_keywordzerobin.netaccessing paste raw contentT1119TA0009N/AN/ACollectionhttps://zerobin.net/11#PastebinLikeN/A88N/AN/AN/AN/A
28
*https://zerobin.net/js/privatebin.js*.{0,1000}https\:\/\/zerobin\.net\/js\/privatebin\.js.{0,1000}greyware_tool_keywordzerobin.netsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationhttps://zerobin.net/11#PastebinLikeN/A88N/AN/AN/AN/A
29
*IEX*nopaste.net*.{0,1000}IEX.{0,1000}nopaste\.net.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingserviceN/A810N/AN/AN/AN/A
30
*IWR*nopaste.net*.{0,1000}IWR.{0,1000}nopaste\.net.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingserviceN/A810N/AN/AN/AN/A
31
*nc -N nopaste.net *.{0,1000}nc\s\-N\snopaste\.net\s.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://www.shellhub.io/10#Pastebinlike #filehostingservice #linuxN/A810N/AN/AN/AN/A
32
*nopaste.net*IWR*.{0,1000}nopaste\.net.{0,1000}IWR.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingserviceN/A810N/AN/AN/AN/A
33
*paste.ee/d/*.{0,1000}paste\.ee\/d\/.{0,1000}greyware_tool_keywordpaste.eefetching data from paste.eeT1041TA0009N/AN/ACollectionpaste.ee11#PastebinLikeN/A810N/AN/AN/AN/A
34
*paste.ee/paste*.{0,1000}paste\.ee\/paste.{0,1000}greyware_tool_keywordpaste.eeposting data on paste.eeT1041TA0010N/AN/AData Exfiltrationpaste.ee11#PastebinLikeN/A1010N/AN/AN/AN/A
35
*pastebin.com*/raw/* .{0,1000}pastebin\.com.{0,1000}\/raw\/.{0,1000}\sgreyware_tool_keywordpastebinpastebin raw access content - abused by malwares to retrieve payloadsT1119TA0009Redline StealerBlack BastaCollectionpastebin.com11#PastebinLikegreyware tool - risks of False positive !810N/AN/AN/AN/A
36
*pastebin.com*/rw/*.{0,1000}pastebin\.com.{0,1000}\/rw\/.{0,1000}greyware_tool_keywordpastebinpastebin raw access content - abused by malwares to retrieve payloadsT1119TA0009Redline StealerBlack BastaCollectionpastebin.com11#PastebinLikegreyware tool - risks of False positive !810N/AN/AN/AN/A
37
*pastebin.com*api/api_post.php*.{0,1000}pastebin\.com.{0,1000}api\/api_post\.php.{0,1000}greyware_tool_keywordpastebinpastebin POST url - abused by malwares to exfiltrate informationsT1102 - T1048 - T1094 - T1608.001TA0011N/ABlack BastaData Exfiltrationpastebin.com11#PastebinLikegreyware tool - risks of False positive !810N/AN/AN/AN/A
38
*pastebin.pl/cdn-cgi/challenge-platform/*.{0,1000}pastebin\.pl\/cdn\-cgi\/challenge\-platform\/.{0,1000}greyware_tool_keywordpastebin.plsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationhttps://pastebin.pl/11#PastebinLikeN/A88N/AN/AN/AN/A
39
*pastebin.pl/view/raw/*.{0,1000}pastebin\.pl\/view\/raw\/.{0,1000}greyware_tool_keywordpastebin.placcessing paste raw contentT1119TA0009N/AN/ACollectionhttps://pastebin.pl/11#PastebinLikeN/A88N/AN/AN/AN/A