s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.gitpaste12

📛 Threat Title

Malware family: Gitpaste-12

Category: Gitpaste-12 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.gitpaste12`. Printable name: Gitpaste-12.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:blogs.juniper.net

    Gitpaste-12 is a new worm recently discovered by Juniper Threat Labs, whichuses GitHub and Pastebin for housing component code and has at least 12 different attack modules available.

  • web:cyberacademy.co

    Wormable Gitpaste-12 Botnet Returns to Target Linux Servers, IoT Devices A new wormable botnet that spreads via GitHub and Pastebin to install cryptocurrency miners and backdoors on target systems has returned with expanded capabilities to compromise web applications, IP cameras, and routers.

  • web:cybersecuritynews.com

    This new malware has been named Gitpaste-12 , as it uses the GitHub, Pastebin, and other 12 ways that help it to compromise the system. Juniper Threat Labs detected the first GitPaste-12 attacks on October 15, 2020; that's why the cybersecurity researchers have reported both the Pastebin URL as well as the git repo.

  • web:malpedia.caad.fkie.fraunhofer.de

    Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT devices. It uses GitHub and Pastebin as dead drop C2 locations.

  • web:secoperations.wordpress.com

    The newer version of Gitpaste-12 has exploits for "at least 31 known vulnerabilities — seven of which were also seen in the previous Gitpaste-12 sample — as well as attempts to compromise open Android Debug Bridge connections and existing malware backdoors," explains Langton. The list of exploits, provided by the researchers includes:

  • web:static.s123-cdn.com

    BREAKDOWN Juniper Threat Labs discovered the worm dubbed " Gitpaste-12 " in mid-October. The initial phase of the attack is to compromise a system by exploiting 11 known vulnerabilities that affect Apache Struts (CVE-2017-5638), Asus routers (CVE-2013-5948) the Webadmin plugin for opendreambox (CVE-2017-14135 and Tendra routers (CVE-2020-10987). There is also the possibility of attempted ...

  • web:www.bitdefender.com

    Security researchers have identified yet another campaign from the Gitpaste-12 worm operators, but this time they're trying to leverage more vulnerabilities and even compromise open Android Debug Bridge connections.

  • web:www.bleepingcomputer.com

    Recently discovered Gitpaste-12 worm that spreads via GitHub and also hosts malicious payload on Pastebin, has returned with over 30 vulnerability exploits, according to researchers at Juniper Labs.

  • web:www.cloudsek.com

    Gitpaste-12 is a wormable malware which has the ability to form a network of bots for crypto-mining which is now targeting Multiple Known Vulnerabilities.

  • web:www.sonatype.com

    Gitpaste-12 , a worming botnet, is extremely versatile in its advanced capabilities as it leverages trustworthy sites like GitHub and Pastebin to host it.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.