PULSE NAME
Botnets Continue to Target Aging D-Link Vulnerabilities
WHITE AlienVault 2024-12-31 Modified: 2025-01-30
83
IOCs
HIGH VOLUME
Two botnets, FICORA and CAPSAICIN, have been exploiting long-standing vulnerabilities in D-Link routers to spread globally. FICORA, a Mirai variant, uses a shell script to download and execute malware on various Linux architectures, incorporating DDoS attack functions. CAPSAICIN, likely based on the Keksec group's botnets, also targets multiple Linux architectures and includes DDoS capabilities. Both botnets exploit weaknesses in the HNAP interface of affected D-Link devices, demonstrating the persistent threat posed by unpatched vulnerabilities. The attackers use servers in the Netherlands and target countries worldwide, with CAPSAICIN focusing on East Asian countries. Regular device updates and comprehensive monitoring are crucial for mitigating these threats.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
FICORA CAPSAICIN
Indicators of Compromise (17 / 83 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1b77238da15d598fe3877548b9b2197c 2024-12-31
FileHash-MD5 21f772d53fac58dd9020874ef8f1bfbb 2024-12-31
FileHash-MD5 42d36ae2eaf7090322d2638f5fb36a82 2024-12-31
FileHash-MD5 4b2bfa94425ea635064b9ed7c5ae58fe 2024-12-31
FileHash-MD5 4f972bcb14039a4fad62686929df5f9b 2024-12-31
FileHash-MD5 5494047b610a7a1a6609f5f87ff986da 2024-12-31
FileHash-MD5 61e7d18a4efdd3273fe436a0d66da732 2024-12-31
FileHash-MD5 6439104bfdb93a4fb435f69ee95713d4 2024-12-31
FileHash-MD5 86973f12baa70ab53c827b32edc6a55c 2024-12-31
FileHash-MD5 b09601461725ffb5ed51390172eb4b53 2024-12-31
FileHash-MD5 ce62420c6d3605bb4ca011f680a38dd5 2024-12-31
FileHash-MD5 cff313365a8c2d4a4983d78b29d3fb2c 2024-12-31
FileHash-MD5 d38e8407bbc72cbd2057efdd3d8b7a05 2024-12-31
FileHash-MD5 dd78a6bd7fee0dc8c058cf4f08429992 2024-12-31
FileHash-MD5 de0f5a7725ab51649f6e2f650fae6234 2024-12-31
FileHash-MD5 e15afeee577ac2d7fbab1da293cbb903 2024-12-31
FileHash-MD5 fa8bae6bbcf9a658fa25b7f2a4faaf04 2024-12-31