Paste Bins
Observable Types: domain
Description
Public “paste bin” services allow (usually) anonymous posting and retrieval of arbitrary text.
These services are commonly abused as dead-drop resolvers, staging locations for second-stage payloads and scripts, and low-cost exfiltration destinations. Many are permitted by default because they aren’t categorized well by security vendors.
These are not IOCs, but legitimate services that may be leveraged by an actor. Use this list to mitigate organizational risk accordingly.
Techniques
References
- https://authentic8.com/blog/what-is-pastebin-cyberthreat-intelligence/
- https://socradar.io/blog/top-5-paste-sites-used-by-threat-actors/
- https://community.hpe.com/t5/hpe-threat-labs/new-pastebin-like-service-used-in-multiple-malware-campaigns/ba-p/7265783