Version 15. January 28, 2012
The full table in xls format - Version 15 can be downloaded from here.
xlsx format
in csv format Packs Sheet 1 References sheet 2
Additions - with many thanks to Kahu Security
Hierarchy Exploit Pack
=================
CVE-2006-0003
CVE-2009-0927
CVE-2010-0094
CVE-2010-0188
CVE-2010-0806
CVE-2010-0840
CVE-2010-1297
CVE-2010-1885
CVE-2011-0611
JavaSignedApplet
Siberia Private
==========
CVE-2005-0055
CVE-2006-0003
CVE-2007-5659
CVE-2008-2463
CVE-2008-2992
CVE-2009-0075
CVE-2009-0927
CVE-2009-3867
CVE-2009-4324
CVE-2010-0806
Techno XPack
===========
CVE-2008-2992
CVE-2010-0188
CVE-2010-0842
CVE-2010-1297
CVE-2010-2884
CVE-2010-3552
CVE-2010-3654
JavaSignedApplet
"Yang Pack"
=========
CVE-2010-0806
CVE-2011-2110
CVE-2011-2140
CVE-2011-354
Version 14. January 19, 2012
Credits for the excellent Wild Wild West (October 2011 edition) go to kahusecurity.com
With many thanks to XyliBox (Xylitol - Steven), Malware Intelligence blog, and xakepy.cc for the information:
If you find any errors or CVE information for packs not featured , please send it to my email (in my profile above, thank you very much) .
- Blackhole 1.2.1 (Java Rhino added, weaker Java exploits removed)
- Blackhole 1.2.1 (Java Skyline added)
- Sakura Exploit Pack 1.0 (new kid on the block, private pack)
- Phoenix 2.8. mini (condensed version of 2.7)
- Fragus Black (weak Spanish twist on the original, black colored admin panel, a few old exploits added)
The full table in xls format - Version 14 can be downloaded from here.
The exploit pack table in XLSX format
The exploit pack table in csv format
P.S. There are always corrections and additions thanks to your feedback after the document release, come back in a day or two to check in case v.15 is out.
Version 13. Aug 20, 2011
Kahusecurity issued an updated version of their Wild Wild West graphic that will help you learn Who is Who in the world of exploit packs. You can view the full version of their post in the link above.
Version 13 exploit pack table additions:
- Bleeding Life 3.0
- Merry Christmas Pack (many thanks to kahusecurity.com)+
- Best Pack (many thanks to kahusecurity.com)
- Sava Pack (many thanks to kahusecurity.com)
- LinuQ
- Eleonore 1.6.5
- Zero Pack
- Salo Pack (incomplete but it is also old)
List of packs in the table in alphabetical order
- Best Pack
- Blackhole Exploit 1.0
- Blackhole Exploit 1.1
- Bleeding Life 2.0
- Bleeding Life 3.0
- Bomba
- CRIMEPACK 2.2.1
- CRIMEPACK 2.2.8
- CRIMEPACK 3.0
- CRIMEPACK 3.1.3
- Dloader
- EL Fiiesta
- Eleonore 1.3.2
- Eleonore 1.4.1
- Eleonore 1.4.4 Moded
- Eleonore 1.6.3a
- Eleonore 1.6.4
- Eleonore 1.6.5
- Fragus 1
- Icepack
- Impassioned Framework 1.0
- Incognito
- iPack
- JustExploit
- Katrin
- Merry Christmas Pack
- Liberty 1.0.7
- Liberty 2.1.0*
- LinuQ pack
- Lupit
- Mpack
- Mushroom/unknown
- Open Source Exploit (Metapack)
- Papka
- Phoenix 2.0
- Phoenix 2.1
- Phoenix 2.2
- Phoenix 2.3
- Phoenix 2.4
- Phoenix 2.5
- Phoenix 2.7
- Robopak
- Salo pack
- Sava Pack
- SEO Sploit pack
- Siberia
- T-Iframer
- Unique Pack Sploit 2.1
- Webattack
- Yes Exploit 3.0RC
- Zero Pack
- Zombie Infection kit
- Zopack
----------------------------------------------
Bleeding Life 3.0
New Version Ad is here
Merry Christmas Pack
read analysis atkahusecurity.com |
Best Pack
kahusecurity.comread analysis at |
Sava Pack read analysis at kahusecurity.com |
Eleonore 1.6.5
[+] CVE-2011-0611
[+] CVE-2011-0559 [+] CVE-2010-4452 [-] CVE-2010-0886 |
Salo Pack Old (2009), added just for the collection | Zero Pack 62 exploits from various packs (mostly Open Source pack) |
LinuQ pack
Designed to compromise linux servers using vulnerable PHPMyAdmin. Comes with DDoS bot but any kind of code can be loaded for Linux botnet creation.LinuQ pack is PhpMyAdmin exploit pack with 4 PMA exploits based on a previous Russian version of the Romanian PMA scanner ZmEu. it is not considered to be original, unique, new, or anything special. All exploits are public and known well. It is designed to be installed on an IRC server (like UnrealIRCD). IP ranges already listed in bios.txt can be scanned, vulnerable IPs and specific PMA vulnerabilities will be listed in vuln.txt, then the corresponding exploits can be launched against the vulnerable server. It is more like a bot using PMA vulnerabilities than exploit pack. It is using CVE-2009-1148 (unconfirmed) CVE-2009-1149 (unconfirmed) CVE-2009-1150 (unconfirmed) CVE-2009-1151 (confirmed) |
||
====================================================================
Version 12. May 26, 2011
additional changes (many thanks to kahusecurity.com)
Bomba
Papka
See the list of packs covered in the list below
The full table in xls format - Version 12 can be downloaded from here.
Version 11 May 26, 2011 Changes:
====================================================================
10. May 8, 2011 Version 10 Exploit Pack Table_V10May11
First, I want to thank everyone who sent and posted comments for updates and corrections.
*** The Wild Wild West picture is from a great post about evolution of exploit packs by Kahu Security Wild Wild West Update
As usual, send your corrections and update lists.
See the list of packs covered in the list below
The full table in xls format - Version 12 can be downloaded from here.
I want to thank everyone who sent packs and information :)
Version 11 May 26, 2011 Changes:
- Phoenix2.7
- "Dloader" (well, dloader is a loader but the pack is some unnamed pack http://damagelab.org/lofiversion/index.php?t=20852)
- nuclear pack
- Katrin
- Robopak
- Blackhole exploit kit 1.1.0
- Mushroom/unknown
- Open Source Exploit kit
====================================================================
10. May 8, 2011 Version 10 Exploit Pack Table_V10May11
First, I want to thank everyone who sent and posted comments for updates and corrections.
*** The Wild Wild West picture is from a great post about evolution of exploit packs by Kahu Security Wild Wild West Update
As usual, send your corrections and update lists.
Go1Pack (not included) as reported as being a fake pack, here is a gui. Here is a threatpost article referencing it as it was used for an attack
- Eleonore 1.6.4
- Eleonore 1.6.3a
- Incognito
- Blackhole
Also, here is another article claiming it is not a fake http://community.websense.com/blogs/securitylabs/archive/2011/04/19/Mass-Injections-Leading-to-g01pack-Exploit-Kit.aspx
Go1 Pack CVE are reportedly
CVE-2006-0003
CVE-2009-0927
CVE-2010-1423
CVE-2010-1885
Does anyone have this pack or see it offered for sale?
Exploit kits I am planning to analyze and add (and/or find CVE listing for) are:
- Open Source Exploit Kit
- SALO
- K0de
Legend:
Black color entries by Francois Paget
Red color entries by Gunther
Blue color entries by Mila
Also, here is a great presentation by Ratsoul (Donato Ferrante) about Java Exploits (http://www.inreverse.net/?p=1687)
--------------------------------------------------------
9. April 5, 2011 Version 9 ExploitPackTable_V9Apr11
It actually needs another update but I am posting it now and will issue version 10 as soon as I can.
Changes:
Phoenix 2.5
IFramer
Tornado
Bleeding life
Many thanks to Gunther for his contributions.
If you wish to add some, please send your info together with the reference links. Also please feel free to send corrections if you notice any mistakes
8. Update 8 Oct 22, 2010 Version 8 ExploitPackTable_V8Oct22-10
Changes:
- Eleonore 1.4.4 Moded added (thanks to malwareint.blogspot.com)
- Correction on CVE-2010-0746 in Phoenix 2.2 and 2.3. It is a mistake and the correct CVE is CVE-2010-0886 (thanks to
etonshell for noticing)
- SEO Sploit pack added (thanks to whsbehind.blogspot.com, evilcodecave.blogspot.com and blog.ahnlab.com)
7. Update 7 Oct 18, 2010 Version 7 ExploitPackTable_V7Oct18-10 released
thanks to SecNiche we have updates for Phoenix 2.4 :)
We also added shorthand/slang/abbreviated names for exploits for easy matching of exploits to CVE in the future. Please send us more information re packs, exploit names that can be added in the list. Thank you!
Thanks to Francois Paget (McAfee) we have updates for Phoenix 2.2 and Phoenix 2.3
5. Update 5. Sept 27, 2010 Version 5 ExploitPackTable_V5Sept26-10 released
Added updates for Phoenix 2.1 and Crimepack 3.1.3
4 Update 4 July 23, 2010 Version 4 ExploitPackTable_V4Ju23-10 released. Added a new Russian exploit kit called Zombie Infection Kit to the table. Read more at malwareview.com
Update 3 July 7, 2010. Please read more about this on the Brian Krebs'
blog Pirate
Bay Hack Exposes User Booty
Update 2 June 27, 2010 Sorry but Impassioned Framework is
back where it belongs - blue
Update 1 June 24, 2010 Eleonore 1.4.1 columns was updated to include the correct list of the current exploits.
Francois Paget www.avertlabs.com kindly agreed to allow us to make additions to his Overview of Exploit Packs table published on Avertlabs (McAfee Blog)
Many thanks to Gunther from ARTeam for his help with the update. There are a few blanks and question marks, please do no hesitate to email me if you know the answer or if you see any errors.
Please click on the image below to expand it (it is a partial screenshot) Impassioned Framework is tentatively marked a different color because the author claims it is a security audit tool not exploit pack. However, there was no sufficient information provided yet to validate such claims. The pack is temporarily/tentatively marked a different color. We'll keep you posted.









Phoenix Exploit’s Kit v2.3. It was released in early July 2010 at a cost of USD 2.200.
ReplyDeleteOne of the most important changes in this release was PDF libtiff support the use of bypass
ASLR, DEP more for PDF file reader Adobe Reader on your version 8.0-9.3.0 for Windows Vista
and Windows7.
• IE MDAC CVE-2006-0003
• Adobe Flash 9 CVE-2007-0071
• Adobe Flash 10 CVE-2009-1869
• Adobe Reader CollectEmailInfo CVE-2007-5659
• Adobe Reader util.printf CVE-2008-2992
• Adobe Reader Collab GetIcon CVE-2009-0927
• Adobe Reader newPlayer CVE-2009-4324
• Adobe Reader LibTiff CVE-2010-0188
• Adobe PDF SWF CVE-2010-1297
• Adobe Reader/Foxit Reader PDF OPEN CVE-2009-0836
• Java HsbParser.getSoundBank (GSB) CVE-2009-3867
• Java Runtime Environment (JRE) CVE-2008-5353
• Java SMB CVE-2010-0746
• IE iepeers CVE-2010-0806
• Windows Help Center (HCP) CVE-2010-1885
• IE SnapShot Viewer ActiveX CVE-2008-2463 optional
Highly appreciate your efforts to provide this valuable table and keep it up-to-date.
ReplyDeleteThank you.
I'd found http://ratnetw0rk.blogspot.com/ doing a similar effort - look out for the "CVE Exploit Kit list" on the right. Maybe you guys should team up if you have'nt already.
The libtiff DEP bypass wasn't included until late july in Phoenix.
ReplyDeleteHere is the XLS in Google Docs:
ReplyDeletehttps://spreadsheets.google.com/ccc?key=txCKbjxeFWCpd4tprRHmzOg&hl=en#gid=0
I was curious as to the price of these exploit packs?
Mila,
ReplyDeleteDo you know any "An overview of botnets" that anyone is tracking/keeping anywhere? I'd love to have something like this for the various botnets currently out there.
Mila,
ReplyDeleteDo you expect to add the Blackhole exploit kit to the list?
http://research.zscaler.com/2011/04/uspsgov-website-infected-with-blackhole.html
Websense outlines the list of exploits in the Blackhole Exploit Kit(Feb 2011)
ReplyDeletehttp://community.websense.com/blogs/securitylabs/pages/black-hole-exploit-kit.aspx
List is near the bottom of the blog post.
INCOGNITO
ReplyDeleteCVE-2004-0549
CVE-2007-5659/2008-0655
CVE-2008-2992
CVE-2009-0927
CVE-2009-4324
CVE-2010-0842
CVE-2010-0886
CVE-2010-1885
BLACKHOLE
CVE-2006-0003
CVE-2007-5659/2008-0655
CVE-2008-2992
CVE-2009-0927
CVE-2009-1671
CVE-2010-0840
CVE-2010-0842
CVE-2010-0886
CVE-2010-1423
CVE-2010-1885
-Tex-
G01PACK
ReplyDeleteCVE-2006-0003
CVE-2009-0927
CVE-2010-1423
CVE-2010-1885
-Tex-
CVE-2010-0806 (IEPeers) in Blackhole v1.1.0 is missing from Update 12.
ReplyDeleteSource: http://scriptkiddiesec.blogspot.com/2011/05/black-hole-exploit-kit-110.html
Ohhh my mistake. IEPeers was removed from v1.1.0, which means it was in v1.0.x most likely. That fact is missing from the XLS.
ReplyDeleteSee Blackhole Release Notes near end of entry: http://scriptkiddiesec.blogspot.com/2011/05/black-hole-exploit-kit-110.html
Really great blog. My friends referred me your site. Looks like everyone knows about it. I'm going to read your other posts. Take care. Keep sharing.
ReplyDeletehello friend came 2 more sources
ReplyDeletethat news came out on twitter and I looked on these packs:).....
Captures
http://img101.imageshack.us/img101/120/buscando.png
http://img90.imageshack.us/img90/1226/notforsale.png
http://www.youtube.com/watch?v=KRMz5wNSMWA&feature=player_embedded
http://www.youtube.com/watch?v=888zyBQALqc&feature=player_embedded
ha these are great videos and info, thanks :D
ReplyDeleteHi Mila, Good work by collecting the Exploit Kits.
ReplyDeleteI'm not trying to be childish but I can't open the xls file for "The full table in xls format - Version 14 ", so I am re-edit that xls by text editor to review the data of it, like below:
https://lh3.googleusercontent.com/-Y0vyRB4EPIw/Tx1QFF89OhI/AAAAAAAADR4/8Buo2rEij2M/s506/002.jpg
Kinda hard, so It would be appreciate it if you can save the xls into CSV? Thank's!
Good work!Appreciate your blog.
ReplyDelete