Researchers discover over 47,300 GitHub repositories offering fake PoC exploits

Share post:

Researchers from the Leiden Institute of Advanced Computer Science have discovered thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for vulnerabilities and malware.

Various malicious programs and malicious scripts from remote trojans to Cobalt Strike have been discovered by the researchers.

More than 47,300 repositories advertising an exploit for a vulnerability discovered between 2017 and 2021 were analyzed by the researchers using three mechanisms: IP address analysts to compare publisher IP to public blocklists and VT and AbuseIPDB; binary analysis to perform VirusTotal checks of the provided executable files and their hashes; hexadecimal and base64 analysis: decrypt obfuscated files before performing binary and IP checks.

The researchers discovered 150,734 unique IP addresses that were extracted and 2,864 matched blocklist entries, of which 1,522 were detected as malicious in antivirus scans on Virus Total, and 1,069 were present in the AbuseIPDB database.

The binary analysis examined a number of 6,160 executable files and found a total of 2,164 malicious samples hosted in 1,398 repositories. Overall, 4,893 of the 47,313 tested repositories were classified as malicious, with most of them associated with bugs as of 2020.

As a security precaution, users are advised not to trust a GitHub repository from an unverified source. Software testers are also advised to carefully check the PoCs they download and perform multiple checks before running them.

The sources for this piece include an article in BleepingComputer.


Related articles

Cyber Security Today, June 21, 2024 – US to ban Kaspersky for businesses, consumers

U.S. to ban the sale of Kaspersky products to consumers and businesses. Welcome to Cyber Security Today. It's Friday...

Biden administration to ban US sales of Kaspersky software over ties to Russia

The Biden administration is set to announce a ban on the sale of Kaspersky Lab's antivirus software in...

Security bug may allow anyone to spoof Microsoft employee emails

A security researcher claims to have discovered a bug that enables anyone to impersonate Microsoft corporate email accounts,...

Cyber Security Today, June 19, 2024 – How an attacker hid on an IT network for three years

How an attacker hid on an IT network for three years Welcome to Cyber Security Today. It's Wednesday June...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways