Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: Many Malware Samples Found on Pastebin - SANS Internet Storm Center SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Many Malware Samples Found on Pastebin is a wonderful website. I'm scrapping all posted pasties (not only from and pass them to a bunch of regular expressions. As I said in a previous diary[1], it is a good way to perform open source intelligence. Amongst many configuration files, pieces of code with hardcoded credentials, dumps of databases or passwords, sometimes it pays and you find more interesting data.

For a few days, I'm finding many pasties that contain only Base64 data. The decoded data are malicious PE files. Some files were posted multiple times, others were unique. Some examples from my list:

  • hxxp://
  • hxxp://
  • hxxp://
  • hxxp://
  • hxxp://

Most of the malicious files are known on VT (submitted a few hours ago), others are unknown. I also detected some obfuscated pasties:The Base64 code is reversed:

  • hxxp://

Another technique is the hex-encode the Base64 data:

  • hxxp://
  • hxxp://

This technique has already been seen in the past[2]. Powershell or Javascript scripts download malicious content from But, until now, I was not able to find any reference to the pasties above. Please share with us if you have more information!

In the meantime, it could be a good idea to keep an eye on your logs and search for HTTP requests to these URLs (or globally to if this service is not used in your environment).


Xavier Mertens (@xme)
ISC Handler - Freelance Security Consultant

I will be teaching next: Reverse-Engineering Malware: Malware Analysis Tools and Techniques - SANS Amsterdam August 2022


697 Posts
ISC Handler
Feb 5th 2017
More samples using pastebin can be found in virustotal. many rats like XtremeRAT etc are seen using pastebin to store their base 64 file, later downloaded since 2013-14.

Sign Up for Free or Log In to start participating in the conversation!