Check the status of CVEs. Learn More.
Keeping your systems up 100% of the time requires live patching. Our solutions will align strongly with your risk, compliance, and operational uptime requirements.
TuxCare is trusted by the most innovative companies across the globe.
Learn about TuxCare's modern approach to reducing cybersecurity risk with Blogs, White Papers, and more.
Continually increasing Cybersecurity, stability, and availability of Linux servers and open source software since 2009.
TuxCare provides live security patching for numerous industries. Learn how TuxCare is minimizing risk for companies around the world.
2x a month. No spam.
November 11, 2022 - TuxCare expert team
Researchers from the Leiden Institute of Advanced Computer Science have discovered thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for vulnerabilities and malware.
Various malicious programs and malicious scripts from remote trojans to Cobalt Strike have been discovered by the researchers.
More than 47,300 repositories displaying an exploit for a vulnerability discovered between 2017 and 2021 were analyzed by the researchers using three mechanisms: IP address analysts for comparing the PoC’s publisher IP of the PoC with public blocklists and VT and AbuseIPDB; binary analysis to perform VirusTotal checks of the provided executable files and their hashes; hexadecimal and base64 analysis: decrypt obfuscated files before performing binary and IP checks.
The researchers discovered 150,734 unique IP addresses that were extracted and 2,864 matched blocklist entries, of which 1,522 were detected as malicious in antivirus scans on Virus Total, and 1,069 were present in the AbuseIPDB database.
The binary analysis examined a number of 6,160 executable files and found a total of 2,164 malicious samples hosted in 1,398 repositories. Overall, 4,893 of the 47,313 tested repositories were classified as malicious, with most of them associated with bugs as of 2020.
The report contains a small number of repositories with fake PoCs that provided malware, and the researchers said 60 more are being removed from GitHub.
While investigating the cases, researchers discovered several malicious programs and scripts, ranging from remote access trojans to Cobalt Strike. Cases investigated include a PoC for CVE-2019-0708 known as “BlueKeep,” which contains a base64-disguised Python script that fetches a VBScript from Pastebin. The script is the Houdini RAT, an old JavaScript-based trojan that supports remote command execution via the Windows CMD.
As a security precaution, users are advised not to trust a GitHub repository from an unverified source. Software testers are also advised to carefully check the PoCs they download and perform multiple checks before running them.
The sources for this piece include an article in BleepingComputer.
Watch this news on our Youtube channel: https://www.youtube.com/watch?v=R6OGGQHjMYY
Learn About Live Patching with TuxCare
According to CyberArk researchers, GPT-based models like ChatGPT can be...
Malicious hackers have started exploiting a critical vulnerability CVE-2022-44877 in...
Deep Instinct researchers reported that RATs like StrRAT and Ratty...
According to CircleCI’s CTO, Rob Zuber, CircleCI is working with...
A remote attacker could exploit multiple vulnerabilities in four Cisco...
In a notable IcedID malware attack, the assailant impacted the...