TF-MAL-elf.gitpaste12
📛 Threat Title
Malware family: Gitpaste-12
Description
ThreatFox malware family `elf.gitpaste12`. Printable name: Gitpaste-12.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blogs.juniper.net
Gitpaste-12 is a new worm recently discovered by Juniper Threat Labs, whichuses GitHub and Pastebin for housing component code and has at least 12 different attack modules available.
-
web:cyberacademy.co
Wormable Gitpaste-12 Botnet Returns to Target Linux Servers, IoT Devices A new wormable botnet that spreads via GitHub and Pastebin to install cryptocurrency miners and backdoors on target systems has returned with expanded capabilities to compromise web applications, IP cameras, and routers.
-
web:cybersecuritynews.com
This new malware has been named Gitpaste-12 , as it uses the GitHub, Pastebin, and other 12 ways that help it to compromise the system. Juniper Threat Labs detected the first GitPaste-12 attacks on October 15, 2020; that's why the cybersecurity researchers have reported both the Pastebin URL as well as the git repo.
-
web:malpedia.caad.fkie.fraunhofer.de
Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT devices. It uses GitHub and Pastebin as dead drop C2 locations.
-
web:secoperations.wordpress.com
The newer version of Gitpaste-12 has exploits for "at least 31 known vulnerabilities — seven of which were also seen in the previous Gitpaste-12 sample — as well as attempts to compromise open Android Debug Bridge connections and existing malware backdoors," explains Langton. The list of exploits, provided by the researchers includes:
-
web:static.s123-cdn.com
BREAKDOWN Juniper Threat Labs discovered the worm dubbed " Gitpaste-12 " in mid-October. The initial phase of the attack is to compromise a system by exploiting 11 known vulnerabilities that affect Apache Struts (CVE-2017-5638), Asus routers (CVE-2013-5948) the Webadmin plugin for opendreambox (CVE-2017-14135 and Tendra routers (CVE-2020-10987). There is also the possibility of attempted ...
-
web:www.bitdefender.com
Security researchers have identified yet another campaign from the Gitpaste-12 worm operators, but this time they're trying to leverage more vulnerabilities and even compromise open Android Debug Bridge connections.
-
web:www.bleepingcomputer.com
Recently discovered Gitpaste-12 worm that spreads via GitHub and also hosts malicious payload on Pastebin, has returned with over 30 vulnerability exploits, according to researchers at Juniper Labs.
-
web:www.cloudsek.com
Gitpaste-12 is a wormable malware which has the ability to form a network of bots for crypto-mining which is now targeting Multiple Known Vulnerabilities.
-
web:www.sonatype.com
Gitpaste-12 , a worming botnet, is extremely versatile in its advanced capabilities as it leverages trustworthy sites like GitHub and Pastebin to host it.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.