A recently discovered worm/botnet called Gitpaste-12 lives on GitHub and also uses Pastebin to host malicious code.
The advanced malware is equipped with reverse shell and cryptocurrency mining capabilities and exploits over 12 known vulnerabilities.

Spreads via GitHub, attacks in 12 different ways
Gitpaste-12 was first spotted by Juniper Threat Labs circulating on GitHub around October 15th.
However, the commits reveal that the malware lived on GitHub from July 9, 2020 until it was removed on October 30, 2020.
The worm attempts to crack passwords through brute-force and exploits known vulnerabilities in the systems it infects.
11 of these vulnerabilities are listed in the table below, with the 12th coming from a Telnet brute force application used to spread Gitpaste-12:

After the initial system compromise, Gitpaste-12 downloads a recursive script from a URL on Pastebin that instructs the infected host to continue executing this script every minute.
This is a way for the malware to continue to update itself from the Command and Control (C2) source which is simply a URL:

Additionally, the malware downloads the main shell script from GitHub.
The URL where the shell script “lived” has since been removed: https://raw.githubusercontent[.]com/cnmnmsl-001/-/master/shadu1
“Malware starts by preparing the environment. This means stripping down its defenses, including firewall, selinux, apparmor, and common attack prevention and monitoring software,” Juniper Threat LabsAlex Burt and Trevor Pott say.
In fact, some of the commands and hostnames present in the script reveal that Gitpaste-12 is designed to attack cloud computing infrastructures provided by Alibaba Cloud and Tencent.
Additionally, the botnet is equipped with a Monero (XMR) cryptocurrency mining program.
But there's more to learn: the worm spreads by targeting a list of IP addresses that are randomly generated within a subnet range.
“The Gitpaste-12 malware also contains a script that launches attacks against other computers, in an attempt to replicate and spread. It chooses a random /8 CIDR to attack and tries all addresses within that range,” Juniper researchers report.
The researchers also noted that some compromised systems had TCP ports 30004 and 30005 open for receiving commands via reverse shells.
Gitpaste-12 has a low detection rate
Some files associated with the Gitpaste-12 botnet have a fairly low detection rate. BleepingComputer observed that the hide.so payload that helps Gitpaste-12 evade detection is 93% missed by antivirus engines.
Similarly, the encryption configuration file and shell script have not yet been flagged by any antivirus engine listed on VirusTotal, as observed by BleepingComputer:

Information source: bleepingcomputer.com
