Malicious files on Metasploit

Hi Team,
I was downloaded Metasploit Framework windows installer link provided by Rapid7 open labs and tried to launch the framework application on my machine.
our CrowdStrike EDR, detected multiple dll’s & .exe’s and also when I see the hash search on Virus Total - it showing malicious/.

i’m out of trust after seeing these and not to install under Windows application.

\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2010-0232\kitrap0d.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2013-1300\schlamperei.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2013-0074\SilverApp1.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2013-0109\nvidia_nvsvc.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2014-4113\cve-2014-4113.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2013-5045\CVE-2013-5045.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2014-0257\CVE-2014-0257.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2015-1701\cve-2015-1701.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2015-1701\cve-2015-1701.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2015-0016\cve-2015-0016.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2016-0040\CVE-2016-0040.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2016-0051\cve-2016-0051.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2016-0189\ielocalserver.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2016-0189\ieshell32.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2019-0841\diaghub_load_x86.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2018-8120\CVE-2018-8120x86.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2018-8440\ALPC-TaskSched-LPE.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2018-8453\CVE-2018-8453.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2018-8453\CVE-2018-8453.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2018-8120\CVE-2018-8120x64.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2020-1048\cve-2020-1048-exe.Win32.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2020-0787\template_x64_windows.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2020-1313\cve-2020-1313-exe.x64.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2020-1048\cve-2020-1048-exe.x64.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2020-1048\cve-2020-1048-exe.x64.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2020-1054\exploit.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2020-0787\CVE-2020-0787.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2021-21551\CVE-2021-21551.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2022-26904\CVE-2022-26904.dll

\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2022-3699\CVE-2022-3699.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\drunkpotato\drunkpotato.x64.dll

\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\dell_protect\dell_protect.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\drunkpotato\drunkpotato.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\evasion\windows\process_herpaderping\ProcessHerpaderpingTemplate_x64.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\evasion\windows\process_herpaderping\ProcessHerpaderping_x64.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\evasion\windows\process_herpaderping\ProcessHerpaderpingTemplate_x86.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\evasion\windows\process_herpaderping\ProcessHerpaderpingTemplate_x86.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\evasion\windows\process_herpaderping\ProcessHerpaderpingTemplate_x86.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2013-3660\ppr_flatten_rec.x86.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2014-4113\cve-2014-4113.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2015-2426\reflective_dll.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2017-8464\template_x64_windows.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2017-8464\template_x64_windows.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2020-0796\CVE-2020-0796.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2019-1458\exploit.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2021-40449\CVE-2021-40449.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2022-21882\CVE-2022-21882.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2022-21882\CVE-2022-21882.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2019-0841\CVE-2019-0841_x86.exe
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\cve-2018-8897\reflective_dll.x64.dll
\Device\HarddiskVolume4\metasploit-framework\embedded\framework\data\exploits\CVE-2023-21768\CVE-2023-21768.x64.dll

VirusTotal - File - c1b9473c3db907a81c0525a6eb6ddc83c73dd1ebb9686e832aad32c9812e7b69
VirusTotal - File - 06f1aaba68a23d85601ad069dd5ff9cff03ef4bd9500a4ee1d4edcd290b521e8
VirusTotal - File - ee24d1d448fffea3983da1a51ff4b2a37426a5651b9d93aee5959389de743f07
VirusTotal - File - 24abab4054bda1b846b012f71dd0687b4fd4069afc5fda8102a0909e2c85cb6a
VirusTotal - File - bb0a9dfe0bcd7e0365394394c30bff1ec983124214c224324c6b6caa6b83249a
VirusTotal - File - 013202d5011537f06dbe3e1da858bee2409d6d941c8094e4a5ad054e5a68538c
VirusTotal - File - 5473ee1a85c0dafa8f7848b28381a9024d4feafed078664b61d4543e29d31ed9
VirusTotal - File - 2e560514da8fa290be043d860743be69d93f08bf68aee6c80eccda2c443f2c05

1 Like

Hi, antivirus doesn’t like Metasploit. It is used by pentesters and hackers so AV tends to flag it because it has working exploits in it. That is why it shouldn’t be installed side-by-side with AV without excluding the directory it is installed in. It will flag malicious because it can be. However, it is just a tool.

1 Like