PULSE NAME
Botnets Continue to Target Aging D-Link Vulnerabilities
WHITE AlienVault 2024-12-31 Modified: 2025-01-30
83
IOCs
HIGH VOLUME
Two botnets, FICORA and CAPSAICIN, have been exploiting long-standing vulnerabilities in D-Link routers to spread globally. FICORA, a Mirai variant, uses a shell script to download and execute malware on various Linux architectures, incorporating DDoS attack functions. CAPSAICIN, likely based on the Keksec group's botnets, also targets multiple Linux architectures and includes DDoS capabilities. Both botnets exploit weaknesses in the HNAP interface of affected D-Link devices, demonstrating the persistent threat posed by unpatched vulnerabilities. The attackers use servers in the Netherlands and target countries worldwide, with CAPSAICIN focusing on East Asian countries. Regular device updates and comprehensive monitoring are crucial for mitigating these threats.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
FICORA CAPSAICIN
Indicators of Compromise (17 / 83 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0b530c095dde1384c8e71a539c4a8fb038fd9fba 2024-12-31
FileHash-SHA1 1d4001d5f25bf6f34badf0c7ee5b2ee2aeeaf740 2024-12-31
FileHash-SHA1 3226d3e460b1f1b8e60c75705be9837217e01f1d 2024-12-31
FileHash-SHA1 461fd5aec8bd401d0780d1afb357c869d301639f 2024-12-31
FileHash-SHA1 517a7fcddbb87ba43fd41f573bd56ca1be78e86e 2024-12-31
FileHash-SHA1 586399e2e8798c86fe93120defcd7efc2b274a79 2024-12-31
FileHash-SHA1 5dd0155cf41286cec8e9850847095d88b56a30d0 2024-12-31
FileHash-SHA1 5eac7f1915a678017c4fe5ebe264f95dd72ceeb7 2024-12-31
FileHash-SHA1 65ce4695e09e52272551a2a37f9660692f74b8f8 2024-12-31
FileHash-SHA1 7611af4df21d38d4aee5c5f2379a5ccf3adf3768 2024-12-31
FileHash-SHA1 7d954650821deea698dc01a41b9d26f0b1f47f30 2024-12-31
FileHash-SHA1 7ddba93d88aa948c675a1cfa48ddd23ca651f80d 2024-12-31
FileHash-SHA1 89e1ebb28cea58b8f9eb728383f8cb565d58518e 2024-12-31
FileHash-SHA1 912ff68ca48b9d60ac0acf7ea30c877c406bbbf2 2024-12-31
FileHash-SHA1 a7df0a931f0a9e375030041c42cf978ec39cbd9c 2024-12-31
FileHash-SHA1 af46ba435aec9b91b9c28602f0656f9be51b28a0 2024-12-31
FileHash-SHA1 cf88f0f596ad5357c5643cf7c5680ac8ec64d9cd 2024-12-31