Raw Paste Service Access

 Original Source: [Sigma source]
Title: Raw Paste Service Access
Status: test
Description:Detects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form
References:
  -https://www.virustotal.com/gui/domain/paste.ee/relations
Author: Florian Roth (Nextron Systems)
Date: 2019-12-05
modified:2023-01-19
Tags:
  • -'attack.command-and-control'
  • -'attack.t1071.001'
  • -'attack.t1102.001'
  • -'attack.t1102.003'
Logsource:
  • category: proxy
Detection:
  selection:
    c-uri|contains:
      -'.paste.ee/r/'
      -'.pastebin.com/raw/'
      -'.hastebin.com/raw/'
      -'.ghostbin.co/paste/*/raw/'
      -'pastetext.net/'
      -'pastebin.pl/'
      -'paste.ee/'

  condition:selection
Falsepositives:
  -User activity (e.g. developer that shared and copied code snippets and used the raw link instead of just copy & paste)
Level: high