Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Pastebin hosted malicious code

by The Gurus
January 8, 2015
in Editor's News
Share on FacebookShare on Twitter

Pastebin was used to store backdoor code that was later tapped in attacks against websites running a vulnerable instance of the popular RevSlider plugin.
 
According to researcher Denis Sinegubko, Pastebin was used as a remote server for malcode. According to The Register, Sinegubko said: “Technically, the criminals used Pastebin for what it was built for – to share code snippets. The only catch is that the code is malicious, and it is used in illegal activity directly off of the Pastebin website. This time we see relatively massive use of Pastebin in live attacks, which is quite new to us.”
 
The code injected the content of a Base64-encoded $temp variable into a WordPress core wp-links-opml.php file and immediately executed. The use of a wp_nonce_once parameter hid the address of malicious pastes in a bid to foil blocking efforts or deletion of pastes and also added flexibility to execute any Pastebin snippet.
 
In an email to IT Security Guru, Bromium co-founder Ian Pratt agreed that this sort of action shows hackers who are not adept at covering their tracks. “Hackers attempting to be stealthy wouldn’t use Pastebin as such accesses are likely to raise red flags to vigilant security pros.
 
“However, many servers and networks are not closely monitored, so the attackers can get away with being lazy. Further, using Pastebin to host malcode leaves less of a forensic trail than going to the effort of setting up your own server in the cloud or compromising some other web site to be duped into doing the hosting.”
 
In 2012, Pastebin founder Jeroen Vader said that he planned to hire more peopl
e to deal with the posting of password lists, source code and personal information, then receiving an average of 1,200 abuse reports a day via Pastebin’s on-site notification system and by email. Vader noted that personal information about himself had been posted to Pastebin, which he “quickly” removed.

 
Asked if he felt that Pastebin could be doing a better job to vet uploads, bearing in mind there are likely to be thousands every hour, Pratt said that it is mathematically impossible for Pastebin to vet code to determine whether it is malicious.
 
Jared DeMott, security researcher at Bromium Labs, said: “Once malware is running, finding how it connects out, and receives new code and commands is a cat and mouse game. If you block Pastebin, they’ll use Github.
 
“Enterprises cannot just block access to Github, like they could Pastebin, since it’s often a business critical need. The best way to stop malware is to stop it at the point of attack, rather than waiting and trying to deal with it once it has a foothold in your life.”

Tags: C&CMalware
ShareTweet
Previous Post

Finnish banks DDoS attacks enabled by Lizard Squad supporters

Next Post

Through the barricades

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol