MalwareMustDie

MalwareMustDie's Pastebin

An archive of MMD pastes until 2014 (inactive, museums)    99,797 418,618 8 years ago
Name / Title Added Expires Hits Syntax  
Check shellshock grep log - #MalwareMustDie Oct 16th, 2014 Never 1,366 Bash -
ITW Campaign of Dyre Malware via Explopit CVE-2013-2729 PDF Oct 15th, 2014 Never 1,490 JavaScript -
PoC of the IptabLeX windows version exists Oct 15th, 2014 Never 821 ASM (NASM) -
Multiple China DDoS-er/backdoor payloads w/long shell cmd Oct 14th, 2014 Never 2,761 JavaScript -
.IptabLes|x comeback frade8c.com:9162 Oct 13th, 2014 Never 337 Bash -
SSH Bruter Block IP List 20141009 #MMD Oct 9th, 2014 Never 1,199 MIX Assembler -
SSH Bruter Block IP List 20141008 #MMD Oct 8th, 2014 Never 1,014 MIX Assembler -
China Windows DDoSer w/USA CNC 23.91.3.246 Oct 5th, 2014 Never 828 ASM (NASM) -
China Crooks White List snagged by MMD Sep 22nd, 2014 Never 7,913 None -
RFI - Bossa Sep 15th, 2014 Never 861 None -
Redundant Exploit Multi-Arc attack of BossaBot Sep 8th, 2014 Never 589 ASM (NASM) -
Redundant dirs for RFI attack BossaBot #Malwaremustdie! Sep 8th, 2014 Never 478 ASM (NASM) -
#MalwareMustDie! Debugging a Ransomware Sep 8th, 2014 Never 737 ASM (NASM) -
#MalwareMustDie! Howto Crack Latest WSO ObfuscationPHP Sep 6th, 2014 Never 1,454 PHP -
Chinese ELF: profild && keymap22 highlights.. Sep 2nd, 2014 Never 734 ASM (NASM) -
China Elf Malware & Kernel Exploit Factory Sep 2nd, 2014 Never 526 JavaScript -
BossaBot Moar ELF IRC skids, #MalwareMustDie Aug 26th, 2014 Never 663 JavaScript -
Mayhem installer Aug 5th 2014 Aug 5th, 2014 Never 803 JavaScript -
Evil SuperFetchExec PHP Script Aug 5th, 2014 Never 2,216 PHP -
Elf Remote DDoS Management Tools from China Jul 29th, 2014 Never 1,110 MIX Assembler -
TAOBAO China ELF DDoS'er Jul 28th, 2014 Never 1,161 MIX Assembler -
#Mayhem Installer | latest one Jul 27th, 2014 Never 464 PHP -
I'm a mu mu mu? Just a Crap! Jul 27th, 2014 Never 535 JavaScript -
How to DOX & gather OnlineDate Site's Scammer Info :-) Jun 21st, 2014 Never 1,421 JavaScript -
Installation of the Autostart Scripts | China DDoSer Jun 16th, 2014 Never 657 ASM (NASM) -
Network Interface grabbed | China DDoSer Jun 16th, 2014 Never 550 ASM (NASM) -
Server sensitive info's grabbed | China DDoSer Jun 16th, 2014 Never 565 ASM (NASM) -
Updater function | China DDoS'er Jun 16th, 2014 Never 621 ASM (NASM) -
Zbic Decompression Data | China DDoSer Jun 16th, 2014 Never 794 ASM (NASM) -
DNS Flood Thread | China DDoSer Jun 16th, 2014 Never 825 ASM (NASM) -
SYN Flood Thread | China DDoSer Jun 16th, 2014 Never 843 ASM (NASM) -
Recent Incident of Linux ELF (LD_PRELOAD) libworker.so Jun 10th, 2014 Never 714 JavaScript -
jinxed source2 of .SO ELF LD_PRELOAD PHP malware installer Jun 10th, 2014 Never 496 PHP -
jinxed source1 of .SO ELF LD_PRELOAD PHP malware installer Jun 10th, 2014 Never 554 PHP -
LD_PRELOAD .SO ELF MALWARE ATTACK FROM ROMANIA Jun 10th, 2014 Never 436 JavaScript -
Zendran DDoS'er ELF Installer Script Jun 6th, 2014 Never 479 PHP -
PowerBot Perl IRCBot | Case #8 - Journey to Abused FTP Jun 4th, 2014 Never 948 Perl -
Perl IRCBot - Case #8: DDoS'er & Spreader Tool Jun 4th, 2014 Never 1,571 Perl -
Case #8 - Journey to Abused FTP Jun 4th, 2014 Never 704 JavaScript -
Snagged: Perl RFI Scanner Bot 0.1 Jun 2nd, 2014 Never 1,218 Perl -
Snagged: Pbot Full Weaponized DDoS Jun 1st, 2014 Never 4,837 PHP -
LD_PRELOAD .SO ELF MALWARE FRESH ATTACK FROM OVH, FRANCE! May 27th, 2014 Never 2,588 PHP -
#MalwareMustDie | ZeusVM w/ 0x02 Signed Sample May 24th, 2014 Never 1,052 MIX Assembler -
Older version installer script of malware libworker.so May 19th, 2014 Never 343 None -
#MMD| xx(32|64)'s Symbol table | Elf analysis May 12th, 2014 Never 3,119 None -
libworker.so ALIVE sites May 10th, 2014 Never 1,558 None -
#MalwareMustDie! libworker.so malware library infected sites May 9th, 2014 Never 1,449 None -
Hacked site of gogo2me Script Deobfuscated May 3rd, 2014 Never 578 Java -
Fake Installer downloads PUP Backdoor May 2nd, 2014 Never 359 JavaScript -
#CVE-2014-1776 May 1st, 2014 Never 3,418 JavaScript -
Mapping of PC Spambot April 2014 Upatre/GMO Apr 25th, 2014 Never 2,328 None -
Evil 302 Cushion TDS Pointing to fbt.yahoo.com/counter.php Apr 24th, 2014 Never 596 JavaScript -
Kelihos Infection APRIL 18th 2014 / last 16h monitoring Apr 17th, 2014 Never 1,046 None -
Kelihos Infection APRIL 17th 2014 / 12h Apr 17th, 2014 Never 1,267 None -
April 14th ~ Recorded #SSH Bruter Attacker Top List Apr 15th, 2014 Never 2,233 None -
And YET another PHP Injected Apr 12th, 2014 Never 605 JavaScript -
Part2: And another PHP Injected | PHP/Redirector #w00t! Apr 12th, 2014 Never 551 JavaScript -
And another PHP Injected | PHP/ShellBot Apr 12th, 2014 Never 606 JavaScript -
American Express Phishing April 12 2014 Apr 12th, 2014 Never 964 JavaScript -
List of recent SSH default user's login attacker's IPs Apr 10th, 2014 Never 1,678 None -
Four full set of spam campaign gameovers Apr 5th, 2014 Never 717 JavaScript -
Upatre HTTPS "ComeBack" Disassm by IDA Apr 3rd, 2014 Never 902 6502 ACME Cross Assembler -
PHP HAcked WP Case Mar 27th, 2014 Never 920 JavaScript -
WPhack:nextstyle.php -- decoded #MalwareMustDie @unixfreaxjp Mar 27th, 2014 Never 1,149 JavaScript -
UPATRE ZZP of ZGMO campaign via Spam attachment Mar 26th, 2014 Never 597 JavaScript -
Upatre downloading Zeus Gameover (GMO) Mar 26th, 2014 Never 578 JavaScript -
Nuclear bai bai Mar 22nd, 2014 Never 444 None -
Nuclear RU part 3 Mar 22nd, 2014 Never 593 None -
Nuclear RU part 2 Mar 22nd, 2014 Never 460 None -
Nuclear OVH & DB Mar 22nd, 2014 Never 638 None -
Nuclear RU part 1 Mar 18th, 2014 Never 618 None -
Blob of PHP Shell Mar 18th, 2014 Never 929 JavaScript -
GoogleCode RECENT Malware Abuse list (only).. Mar 16th, 2014 Never 529 None -
Trojan bankings served in Google Code Mar 16th, 2014 Never 929 None -
#MalwareMustDie! Recent Upatre downloads encrypted Zbot/GMO Mar 14th, 2014 Never 1,192 JavaScript -
Taiwan Kelihos infection Log Mar 12th, 2014 Never 511 None -
"Wattering" RAT HAVEX INFECTION VERDICT Mar 10th, 2014 Never 20,057 Java -
Turkish Trojan PHP SNS set (called page) Mar 10th, 2014 Never 451 JavaScript -
Turkish Trojan JS SNS set (from Landing page) Mar 10th, 2014 Never 497 JavaScript -
Logger, Backdoor SMTP, Downloader from China Mar 8th, 2014 Never 502 JavaScript -
Turkish Banking Trojan CNC Request Analysis Mar 4th, 2014 Never 454 PHP -
Citadel PoC Mar 3rd, 2014 Never 736 None -
When Traffer and Infector crooks work together Mar 2nd, 2014 Never 639 JavaScript -
Amazon/Google abuse: Feb 27th, 2014 Never 945 PHP -
Tango Down Check: Nuclear follow up Feb 27th, 2014 Never 617 JavaScript -
CookieBomb check pad Feb 26th, 2014 Never 506 JavaScript -
#MalwareMustDie - background.js Feb 23rd, 2014 Never 751 JavaScript -
Grey stuff: TDS Used Landing Page JS Code Feb 23rd, 2014 Never 397 JavaScript -
Page replacement..hard way to inject.. Feb 22nd, 2014 Never 367 Java -
Iframer JS Injection Feb 22nd, 2014 Never 473 JavaScript -
CookieBomb pad Feb 22nd, 2014 Never 401 JavaScript -
And another Perl DDoS Shell Bot Feb 21st, 2014 Never 1,207 Perl -
PerlBot Remote Downloader Feb 21st, 2014 Never 498 Perl -
Another PerlBot Shell Feb 21st, 2014 Never 821 Perl -
CookieBomb v2 - First Cushion Cookie Flow Step by Step Feb 20th, 2014 Never 760 Java -
Kuluoz Reversing "QUICK" Notes Feb 14th, 2014 Never 479 ASM (NASM) -
Hacked Site with the US IRC Server'S Perl ShellBot Feb 12th, 2014 Never 1,849 Perl -
#MalwareMustDie - Decoding Kelihos Simda download FakeAV Feb 10th, 2014 Never 1,554 JavaScript -
Have a "xmlrpc.php" & GooDork for Breakfast Feb 6th, 2014 Never 719 XML -
Phishing AMEX Script (neutralized) Feb 5th, 2014 Never 1,550 JavaScript -